Gianluca Vagnoni created PARQUET-2300:
-----------------------------------------
Summary: Update jackson-core 2.13.4 to a version without CVE
PRISMA-2023-0067
Key: PARQUET-2300
URL: https://issues.apache.org/jira/browse/PARQUET-2300
Project: Parquet
Issue Type: Bug
Components: parquet-mr
Affects Versions: 1.13.0
Reporter: Gianluca Vagnoni
The library "{*}parquet-jackson{*}" version 1.13.0 and 1.13.1 contains the
vulnerability PRISMA-2023-0067
([https://github.com/FasterXML/jackson-core/pull/827)]
([https://github.com/IBM/ibm-cos-sdk-java/issues/58)]
Please upgrade the shaded library to jackson-core version 2.15.0 to fix it.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)