[ 
https://issues.apache.org/jira/browse/CURATOR-481?focusedWorklogId=206928&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-206928
 ]

ASF GitHub Bot logged work on CURATOR-481:
------------------------------------------

                Author: ASF GitHub Bot
            Created on: 03/Mar/19 19:14
            Start Date: 03/Mar/19 19:14
    Worklog Time Spent: 10m 
      Work Description: asfgit commented on pull request #280: CURATOR-481 
Remove jackson-mapper-asl-version and update jackson
URL: https://github.com/apache/curator/pull/280
 
 
   
 
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Issue Time Tracking
-------------------

    Worklog Id:     (was: 206928)
    Time Spent: 0.5h  (was: 20m)

> Remove jackson-mapper-asl-version and update to latest version of jackson
> -------------------------------------------------------------------------
>
>                 Key: CURATOR-481
>                 URL: https://issues.apache.org/jira/browse/CURATOR-481
>             Project: Apache Curator
>          Issue Type: Bug
>          Components: General
>    Affects Versions: 2.3.0
>            Reporter: Maxim Pudov
>            Priority: Major
>             Fix For: 4.2.0
>
>          Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> There is a vulnerability issue in jackson-mapper-asl-version 1.9.13 and it is 
> no longer supported. The same issue was present in jackson-databind till 
> version 2.7.9.1.
> [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7525]
> We already have a dependency on jackson 2.x. Let's replace jackson-mapper-asl 
> with jackson-databind and update jackson to the latest version.
>  
>  



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to