[ 
https://issues.apache.org/jira/browse/HADOOP-16891?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17048104#comment-17048104
 ] 

Hudson commented on HADOOP-16891:
---------------------------------

SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #18011 (See 
[https://builds.apache.org/job/Hadoop-trunk-Commit/18011/])
HADOOP-16891. Upgrade jackson-databind to 2.9.10.3 (#1865) (github: rev 
e36b27260845c2eeb2211d01235cc6d3578b1942)
* (edit) hadoop-project/pom.xml


> Upgrade jackson-databind to 2.9.10.3
> ------------------------------------
>
>                 Key: HADOOP-16891
>                 URL: https://issues.apache.org/jira/browse/HADOOP-16891
>             Project: Hadoop Common
>          Issue Type: Bug
>            Reporter: Siyao Meng
>            Assignee: Siyao Meng
>            Priority: Blocker
>             Fix For: 3.3.0, 2.9.3, 3.1.4, 3.2.2, 2.10.1
>
>
> New [RCE|https://nvd.nist.gov/vuln/detail/CVE-2020-8840] found in 
> jackson-databind 2.0.0 through 2.9.10.2.
> Patched in 2.9.10.3. [Looks 
> critical|https://github.com/jas502n/CVE-2020-8840/blob/master/Poc.java#L13].
> After HADOOP-16882 get in we should backport this to those lower-version 
> branches ASAP.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-issues-h...@hadoop.apache.org

Reply via email to