[ https://issues.apache.org/jira/browse/CURATOR-481?focusedWorklogId=200889&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-200889 ]
ASF GitHub Bot logged work on CURATOR-481: ------------------------------------------ Author: ASF GitHub Bot Created on: 19/Feb/19 21:15 Start Date: 19/Feb/19 21:15 Worklog Time Spent: 10m Work Description: cammckenzie commented on issue #280: CURATOR-481 Remove jackson-mapper-asl-version and update jackson URL: https://github.com/apache/curator/pull/280#issuecomment-465313054 I'm not sure. I am not familiar with this area of the code base, and while the change seems fairly benign, my concern is that the changes will cause backwards compatibility issues. Is there any documentation you can point me to that would indicate whether this is the case or not? ---------------------------------------------------------------- This is an automated message from the Apache Git Service. To respond to the message, please log on GitHub and use the URL above to go to the specific comment. For queries about this service, please contact Infrastructure at: us...@infra.apache.org Issue Time Tracking ------------------- Worklog Id: (was: 200889) Time Spent: 20m (was: 10m) > Remove jackson-mapper-asl-version and update to latest version of jackson > ------------------------------------------------------------------------- > > Key: CURATOR-481 > URL: https://issues.apache.org/jira/browse/CURATOR-481 > Project: Apache Curator > Issue Type: Bug > Components: General > Affects Versions: 2.3.0 > Reporter: Maxim Pudov > Priority: Major > Fix For: TBD > > Time Spent: 20m > Remaining Estimate: 0h > > There is a vulnerability issue in jackson-mapper-asl-version 1.9.13 and it is > no longer supported. The same issue was present in jackson-databind till > version 2.7.9.1. > [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7525] > We already have a dependency on jackson 2.x. Let's replace jackson-mapper-asl > with jackson-databind and update jackson to the latest version. > > -- This message was sent by Atlassian JIRA (v7.6.3#76005)