[ https://issues.apache.org/jira/browse/HADOOP-16891?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17048104#comment-17048104 ]
Hudson commented on HADOOP-16891: --------------------------------- SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #18011 (See [https://builds.apache.org/job/Hadoop-trunk-Commit/18011/]) HADOOP-16891. Upgrade jackson-databind to 2.9.10.3 (#1865) (github: rev e36b27260845c2eeb2211d01235cc6d3578b1942) * (edit) hadoop-project/pom.xml > Upgrade jackson-databind to 2.9.10.3 > ------------------------------------ > > Key: HADOOP-16891 > URL: https://issues.apache.org/jira/browse/HADOOP-16891 > Project: Hadoop Common > Issue Type: Bug > Reporter: Siyao Meng > Assignee: Siyao Meng > Priority: Blocker > Fix For: 3.3.0, 2.9.3, 3.1.4, 3.2.2, 2.10.1 > > > New [RCE|https://nvd.nist.gov/vuln/detail/CVE-2020-8840] found in > jackson-databind 2.0.0 through 2.9.10.2. > Patched in 2.9.10.3. [Looks > critical|https://github.com/jas502n/CVE-2020-8840/blob/master/Poc.java#L13]. > After HADOOP-16882 get in we should backport this to those lower-version > branches ASAP. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org