[
https://issues.apache.org/jira/browse/CASSANDRA-15829?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17260952#comment-17260952
]
Ivo Dujmovic commented on CASSANDRA-15829:
------------------------------------------
[~c3-keveker] I do not see why this is a clone of CASSANDRA-15828 which relates
to removing jackson-core-asl-1.9.13.jar (successful in 3.11.7)
bash-4.2$ find / -name 'jackson*'
/opt/cassandra/lib/licenses/jackson-mapper-asl-1.9.13.txt
/opt/cassandra/lib/licenses/jackson-core-asl-1.9.13.txt
/opt/cassandra/lib/jackson-databind-2.9.10.4.jar
/opt/cassandra/lib/jackson-annotations-2.9.10.jar
/opt/cassandra/lib/jackson-core-2.9.10.jar
However this Jira is for upgrade of logback core to 1.2.0 or later. Which is
still open in cassandra 3.11.8:
bash-4.2$ find / -name 'logback-core*'
/opt/cassandra/lib/logback-core-1.1.3.jar
/opt/cassandra/lib/licenses/logback-core-1.1.3.txt
> Upgrade to logback 1.2.3 to address CVE
> ---------------------------------------
>
> Key: CASSANDRA-15829
> URL: https://issues.apache.org/jira/browse/CASSANDRA-15829
> Project: Cassandra
> Issue Type: Improvement
> Reporter: Kevin Eveker
> Priority: Normal
>
> Recent scan results identified the following CVE that requires this upgrade
> to address
> [https://nvd.nist.gov/vuln/detail/CVE-2017-5929]
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]