Dávid Paksy created ZOOKEEPER-5083:
--------------------------------------
Summary: Upgrade Jackson-databind to 2.22.2 to fix known security
vulnerabilities
Key: ZOOKEEPER-5083
URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5083
Project: ZooKeeper
Issue Type: Task
Components: security
Affects Versions: 3.10.0
Reporter: Dávid Paksy
OWASP dependency check found CVE om master in our currently used Jackson
databind version:
jackson-databind-2.18.8.jar
(pkg:maven/com.fasterxml.jackson.core/[email protected],
cpe:2.3:a:fasterxml:jackson-core:2.18.8:*:*:*:*:*:*:*,
cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*,
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.8:*:*:*:*:*:*:*) : CVE-2026-54515
--
This message was sent by Atlassian Jira
(v8.20.10#820010)