Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
Apache Knox currently ships the Jackson databind jar version 2.2.2. However, there is a security advisory CVE-2017-7525 released for this component:
https://github.com/FasterXML/jackson-databind/issues/1599
We should upgrade Jackson to pick this fix up.