This is an automated email from the ASF dual-hosted git repository.
phunt pushed a commit to branch branch-3.5
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/branch-3.5 by this push:
new c01aef8 ZOOKEEPER-3734: upgrade jackson-databind to address
CVE-2020-8840
c01aef8 is described below
commit c01aef824b556f68085a8bbeeaf379172c2bf8a4
Author: Enrico Olivelli <[email protected]>
AuthorDate: Sun Feb 23 08:41:20 2020 -0800
ZOOKEEPER-3734: upgrade jackson-databind to address CVE-2020-8840
Author: Enrico Olivelli <[email protected]>
Reviewers: [email protected]
Closes #1262 from eolivelli/fix/ZOOKEEPER-3734-jackson-again
Change-Id: I21df2c160f8dd9c2542c153e4aa53500b58e8144
(cherry picked from commit f0c6ae5eb205d7c546483a6f1769cb58b68169a6)
Signed-off-by: Patrick Hunt <[email protected]>
---
build.xml | 2 +-
pom.xml | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/build.xml b/build.xml
index cde620e..bf01342 100644
--- a/build.xml
+++ b/build.xml
@@ -55,7 +55,7 @@ xmlns:cs="antlib:com.puppycrawl.tools.checkstyle.ant">
<property name="javacc.version" value="5.0"/>
<property name="jetty.version" value="9.4.17.v20190418"/>
- <property name="jackson.version" value="2.9.10.1"/>
+ <property name="jackson.version" value="2.9.10.3"/>
<property name="dependency-check-ant.version" value="5.2.4"/>
<property name="commons-io.version" value="2.6"/>
diff --git a/pom.xml b/pom.xml
index 0fe63ff..47fe987 100755
--- a/pom.xml
+++ b/pom.xml
@@ -279,7 +279,7 @@
<commons-cli.version>1.2</commons-cli.version>
<jetty.version>9.4.24.v20191120</jetty.version>
<netty.version>4.1.45.Final</netty.version>
- <jackson.version>2.9.10.2</jackson.version>
+ <jackson.version>2.9.10.3</jackson.version>
<json.version>1.1.1</json.version>
<jline.version>2.11</jline.version>
<snappy.version>1.1.7</snappy.version>