[
https://issues.apache.org/jira/browse/HADOOP-16891?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17048104#comment-17048104
]
Hudson commented on HADOOP-16891:
---------------------------------
SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #18011 (See
[https://builds.apache.org/job/Hadoop-trunk-Commit/18011/])
HADOOP-16891. Upgrade jackson-databind to 2.9.10.3 (#1865) (github: rev
e36b27260845c2eeb2211d01235cc6d3578b1942)
* (edit) hadoop-project/pom.xml
> Upgrade jackson-databind to 2.9.10.3
> ------------------------------------
>
> Key: HADOOP-16891
> URL: https://issues.apache.org/jira/browse/HADOOP-16891
> Project: Hadoop Common
> Issue Type: Bug
> Reporter: Siyao Meng
> Assignee: Siyao Meng
> Priority: Blocker
> Fix For: 3.3.0, 2.9.3, 3.1.4, 3.2.2, 2.10.1
>
>
> New [RCE|https://nvd.nist.gov/vuln/detail/CVE-2020-8840] found in
> jackson-databind 2.0.0 through 2.9.10.2.
> Patched in 2.9.10.3. [Looks
> critical|https://github.com/jas502n/CVE-2020-8840/blob/master/Poc.java#L13].
> After HADOOP-16882 get in we should backport this to those lower-version
> branches ASAP.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]