Details
-
Task
-
Status: Resolved
-
Critical
-
Resolution: Duplicate
-
3.5.10, 3.8.0, 3.7.1
-
None
Description
Two High issues
https://nvd.nist.gov/vuln/detail/CVE-2022-42003
https://nvd.nist.gov/vuln/detail/CVE-2022-42004
affect jackson version 2.13.3 which zk should update to 2.13.4.1
Other projects have done this, but Zookeeper has not.
Attachments
Issue Links
- Blocked
-
ZOOKEEPER-4333 QuorumSSLTest - testOCSP fails on JDK17
- Resolved
- duplicates
-
ZOOKEEPER-4661 Upgrade Jackson Databind to 2.13.4.2 for CVE-2022-42003 CVE-2022-42004
- Closed
- is related to
-
ZOOKEEPER-4627 High CVE-2022-2048 in jetty-*-9.4.46.v20220331.jar fixed in 9.4.47
- Closed
- links to