Uploaded image for project: 'ZooKeeper'
  1. ZooKeeper
  2. ZOOKEEPER-4716

Upgrade jackson to 2.15.2, suppress two false positive CVE errors

VotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    Description

      Our jackson is quite old, I want to upgrade it before release 3.8.2.

      Also we have a few false positive CVEs reported by OWASP:

       

      [INFO] Finished at: 2023-06-30T13:23:38+02:00 
      [INFO] ------------------------------------------------------------------------ 
      [ERROR] Failed to execute goal org.owasp:dependency-check-maven:7.1.0:check (default-cli) on project zookeeper: 
      [ERROR] 
      [ERROR] One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '0.0': 
      [ERROR] 
      [ERROR] jackson-core-2.13.4.jar: CVE-2022-45688(7.5) 
      [ERROR] jackson-databind-2.13.4.2.jar: CVE-2023-35116(7.5)
       

       

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            symat Mate Szalay-Beko
            symat Mate Szalay-Beko
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 40m
                40m

                Slack

                  Issue deployment