[
https://issues.apache.org/jira/browse/CURATOR-481?focusedWorklogId=199943&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-199943
]
ASF GitHub Bot logged work on CURATOR-481:
------------------------------------------
Author: ASF GitHub Bot
Created on: 18/Feb/19 08:08
Start Date: 18/Feb/19 08:08
Worklog Time Spent: 10m
Work Description: mikhailvaliev commented on issue #280: CURATOR-481
Remove jackson-mapper-asl-version and update jackson
URL: https://github.com/apache/curator/pull/280#issuecomment-464627810
so you guys are merging this or what?
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
Issue Time Tracking
-------------------
Worklog Id: (was: 199943)
Time Spent: 10m
Remaining Estimate: 0h
> Remove jackson-mapper-asl-version and update to latest version of jackson
> -------------------------------------------------------------------------
>
> Key: CURATOR-481
> URL: https://issues.apache.org/jira/browse/CURATOR-481
> Project: Apache Curator
> Issue Type: Bug
> Components: General
> Affects Versions: 2.3.0
> Reporter: Maxim Pudov
> Priority: Major
> Fix For: TBD
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> There is a vulnerability issue in jackson-mapper-asl-version 1.9.13 and it is
> no longer supported. The same issue was present in jackson-databind till
> version 2.7.9.1.
> [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7525]
> We already have a dependency on jackson 2.x. Let's replace jackson-mapper-asl
> with jackson-databind and update jackson to the latest version.
>
>
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)