Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-40782

Upgrade Jackson-databind to 2.13.4.1

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • 3.4.0
    • 3.3.1, 3.4.0
    • Build
    • None

    Description

      #3590: Add check in primitive value deserializers to avoid deep wrapper array
        nesting wrt `UNWRAP_SINGLE_VALUE_ARRAYS` [CVE-2022-42003]

      Attachments

        Activity

          People

            LuciferYang Yang Jie
            LuciferYang Yang Jie
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: