[
https://issues.apache.org/jira/browse/HADOOP-18529?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Steve Loughran updated HADOOP-18529:
------------------------------------
Summary: Upgrade jackson-databind to a version with fixes for
CVE-2022-42003 and CVE-2022-42004 (was: Upgrade jackson-databind to a version
with CVE-2022-4200(3. 4))
> Upgrade jackson-databind to a version with fixes for CVE-2022-42003 and
> CVE-2022-42004
> --------------------------------------------------------------------------------------
>
> Key: HADOOP-18529
> URL: https://issues.apache.org/jira/browse/HADOOP-18529
> Project: Hadoop Common
> Issue Type: Improvement
> Affects Versions: 3.3.4
> Reporter: Mrudula Madiraju
> Priority: Minor
>
> |CVE-2022-42003|
> |CVE-2022-42004|
> These HIGH severity CVEs are reported against hadoop-client-runtime jars of
> hadoop 3.3.4. These are from Twistlock security scans
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]