[ 
https://issues.apache.org/jira/browse/ZOOKEEPER-5083?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dávid Paksy updated ZOOKEEPER-5083:
-----------------------------------
    Description: 
OWASP dependency check found CVE on master in our currently used Jackson 
databind version:

jackson-databind-2.18.8.jar 
(pkg:maven/com.fasterxml.jackson.core/[email protected], 
cpe:2.3:a:fasterxml:jackson-core:2.18.8:{*}:{*}:{*}:{*}:{*}:{*}:{*}, 
cpe:2.3:a:fasterxml:jackson-databind:2.18.8:{*}:{*}:{*}:{*}:{*}:{*}:{*}, 
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.8:{*}:{*}:{*}:{*}:{*}:{*}:*) : 
CVE-2026-54515

  was:
OWASP dependency check found CVE om master in our currently used Jackson 
databind version:

jackson-databind-2.18.8.jar 
(pkg:maven/com.fasterxml.jackson.core/[email protected], 
cpe:2.3:a:fasterxml:jackson-core:2.18.8:*:*:*:*:*:*:*, 
cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*, 
cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.8:*:*:*:*:*:*:*) : CVE-2026-54515


> Upgrade Jackson-databind to 2.22.2 to fix known security vulnerabilities
> ------------------------------------------------------------------------
>
>                 Key: ZOOKEEPER-5083
>                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5083
>             Project: ZooKeeper
>          Issue Type: Task
>          Components: security
>    Affects Versions: 3.10.0
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>              Labels: pull-request-available
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> OWASP dependency check found CVE on master in our currently used Jackson 
> databind version:
> jackson-databind-2.18.8.jar 
> (pkg:maven/com.fasterxml.jackson.core/[email protected], 
> cpe:2.3:a:fasterxml:jackson-core:2.18.8:{*}:{*}:{*}:{*}:{*}:{*}:{*}, 
> cpe:2.3:a:fasterxml:jackson-databind:2.18.8:{*}:{*}:{*}:{*}:{*}:{*}:{*}, 
> cpe:2.3:a:fasterxml:jackson-modules-java8:2.18.8:{*}:{*}:{*}:{*}:{*}:{*}:*) : 
> CVE-2026-54515



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to