[ https://issues.apache.org/jira/browse/CASSANDRA-20848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18015975#comment-18015975 ]
Stefan Miklosovic edited comment on CASSANDRA-20848 at 8/25/25 11:44 AM: ------------------------------------------------------------------------- [CASSANDRA-20848-20849-4.1|https://github.com/instaclustr/cassandra/tree/CASSANDRA-20848-20849-4.1] {noformat} java11_pre-commit_tests ✓ j11_build 2m 47s ✓ j11_cqlsh_dtests_py311 5m 40s ✓ j11_cqlshlib_cython_tests 11m 20s ✓ j11_cqlshlib_tests 7m 33s ✓ j11_dtests_vnode 40m 12s ✓ j11_jvm_dtests 14m 25s ✓ j11_jvm_dtests_vnode 12m 5s ✓ j11_unit_tests 9m 12s ✕ j11_cqlsh_dtests_py3 6m 21s cql_tracing_test.TestCqlTracing test_tracing_default_impl cql_tracing_test.TestCqlTracing test_tracing_unknown_impl ✕ j11_cqlsh_dtests_py311_vnode 6m 6s cql_tracing_test.TestCqlTracing test_tracing_default_impl ✕ j11_cqlsh_dtests_py38 6m 2s cql_tracing_test.TestCqlTracing test_tracing_simple ✕ j11_cqlsh_dtests_py38_vnode 5m 36s cql_tracing_test.TestCqlTracing test_tracing_default_impl cql_tracing_test.TestCqlTracing test_tracing_simple ✕ j11_cqlsh_dtests_py3_vnode 5m 42s cql_tracing_test.TestCqlTracing test_tracing_default_impl cql_tracing_test.TestCqlTracing test_tracing_simple cql_tracing_test.TestCqlTracing test_tracing_unknown_impl ✕ j11_dtests 58m 44s refresh_test.TestRefresh test_refresh_deadlock_startup java11_separate_tests java8_pre-commit_tests java8_separate_tests {noformat} [java11_pre-commit_tests|https://app.circleci.com/pipelines/github/instaclustr/cassandra/5979/workflows/3ff26147-f340-4a0e-9e7b-b66d0ca54961] not sure what's up with tracing, it does not fail locally, it is unrelated anyway. was (Author: smiklosovic): [CASSANDRA-20848-20849-4.1|https://github.com/instaclustr/cassandra/tree/CASSANDRA-20848-20849-4.1] {noformat} java11_pre-commit_tests ✓ j11_build 2m 47s ✓ j11_cqlsh_dtests_py311 5m 40s ✓ j11_cqlshlib_cython_tests 11m 20s ✓ j11_cqlshlib_tests 7m 33s ✓ j11_dtests_vnode 40m 12s ✓ j11_jvm_dtests 14m 25s ✓ j11_jvm_dtests_vnode 12m 5s ✓ j11_unit_tests 9m 12s ✕ j11_cqlsh_dtests_py3 6m 21s cql_tracing_test.TestCqlTracing test_tracing_default_impl cql_tracing_test.TestCqlTracing test_tracing_unknown_impl ✕ j11_cqlsh_dtests_py311_vnode 6m 6s cql_tracing_test.TestCqlTracing test_tracing_default_impl ✕ j11_cqlsh_dtests_py38 6m 2s cql_tracing_test.TestCqlTracing test_tracing_simple ✕ j11_cqlsh_dtests_py38_vnode 5m 36s cql_tracing_test.TestCqlTracing test_tracing_default_impl cql_tracing_test.TestCqlTracing test_tracing_simple ✕ j11_cqlsh_dtests_py3_vnode 5m 42s cql_tracing_test.TestCqlTracing test_tracing_default_impl cql_tracing_test.TestCqlTracing test_tracing_simple cql_tracing_test.TestCqlTracing test_tracing_unknown_impl ✕ j11_dtests 58m 44s refresh_test.TestRefresh test_refresh_deadlock_startup java11_separate_tests java8_pre-commit_tests java8_separate_tests {noformat} [java11_pre-commit_tests|https://app.circleci.com/pipelines/github/instaclustr/cassandra/5979/workflows/3ff26147-f340-4a0e-9e7b-b66d0ca54961] not sure what's up with tracing, it does not fail locally. > jackson-core vulnerability: CVE-2025-52999 > ------------------------------------------ > > Key: CASSANDRA-20848 > URL: https://issues.apache.org/jira/browse/CASSANDRA-20848 > Project: Apache Cassandra > Issue Type: Bug > Components: Dependencies > Reporter: ANSHUL SAINI > Assignee: Stefan Miklosovic > Priority: Normal > Fix For: 4.0.x, 4.1.x, 5.0.x, 5.x > > > https://nvd.nist.gov/vuln/detail/CVE-2025-52999 > jackson-core contains core low-level incremental ("streaming") parser and > generator abstractions used by Jackson Data Processor. In versions prior to > 2.15.0, if a user parses an input file and it has deeply nested data, Jackson > could end up throwing a StackoverflowError if the depth is particularly large. -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: commits-unsubscr...@cassandra.apache.org For additional commands, e-mail: commits-h...@cassandra.apache.org