[ 
https://issues.apache.org/jira/browse/HADOOP-18529?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Steve Loughran resolved HADOOP-18529.
-------------------------------------
    Resolution: Duplicate

this was covered in HADOOP-18493. please, always check forthcoming releases 
before filing jiras against shipping versions, as they may be fixed already.

see also HADOOP-18332 and the reason why we are staying on the 2.12 line: 2.13 
dependencies break downstream apps and stop them upgrading. 

> Upgrade jackson-databind to a version with CVE-2022-4200(3. 4)
> --------------------------------------------------------------
>
>                 Key: HADOOP-18529
>                 URL: https://issues.apache.org/jira/browse/HADOOP-18529
>             Project: Hadoop Common
>          Issue Type: Improvement
>    Affects Versions: 3.3.4
>            Reporter: Mrudula Madiraju
>            Priority: Minor
>
> |CVE-2022-42003|
> |CVE-2022-42004|
> These HIGH severity CVEs are reported against hadoop-client-runtime jars of 
> hadoop 3.3.4. These are from Twistlock security scans



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-dev-h...@hadoop.apache.org

Reply via email to