Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-5286

Update FasterXML Jackson version to 2.9.5

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    Description

      The current version of FasterXML Jackson-databind used is 2.9.4 which was supposed to fix several critical vulnerabilities but wasn't completely addressed. A fix to address them was introduced in 2.9.5.

      More details about the vulnerability can be found at : https://nvd.nist.gov/vuln/detail/CVE-2018-7489

       

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            sivaprasanna Sivaprasanna Sethuraman
            sivaprasanna Sivaprasanna Sethuraman
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment