Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
Description
Oozie currently has a dependency on an old version of Jackson (2.6.5) - https://github.com/apache/oozie/blob/master/pom.xml#L119
There are a number of CVEs open affecting this version.
https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind/2.6.5