[ 
https://issues.apache.org/jira/browse/CASSANDRA-15829?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17260952#comment-17260952
 ] 

Ivo Dujmovic commented on CASSANDRA-15829:
------------------------------------------

[~c3-keveker] I do not see why this is a clone of CASSANDRA-15828 which relates 
to removing jackson-core-asl-1.9.13.jar  (successful in 3.11.7)

bash-4.2$ find / -name 'jackson*'
/opt/cassandra/lib/licenses/jackson-mapper-asl-1.9.13.txt
/opt/cassandra/lib/licenses/jackson-core-asl-1.9.13.txt
/opt/cassandra/lib/jackson-databind-2.9.10.4.jar
/opt/cassandra/lib/jackson-annotations-2.9.10.jar
/opt/cassandra/lib/jackson-core-2.9.10.jar

However this Jira is for upgrade of logback core to 1.2.0 or later. Which is 
still open in cassandra 3.11.8:

bash-4.2$ find / -name 'logback-core*'
/opt/cassandra/lib/logback-core-1.1.3.jar
/opt/cassandra/lib/licenses/logback-core-1.1.3.txt

> Upgrade to logback 1.2.3 to address CVE
> ---------------------------------------
>
>                 Key: CASSANDRA-15829
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-15829
>             Project: Cassandra
>          Issue Type: Improvement
>            Reporter: Kevin Eveker
>            Priority: Normal
>
> Recent scan results identified the following CVE that requires this upgrade 
> to address
> [https://nvd.nist.gov/vuln/detail/CVE-2017-5929]



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to