[
https://issues.apache.org/jira/browse/TIKA-3869?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17627314#comment-17627314
]
Hudson commented on TIKA-3869:
------------------------------
SUCCESS: Integrated in Jenkins build Tika ยป tika-main-jdk8 #893 (See
[https://ci-builds.apache.org/job/Tika/job/tika-main-jdk8/893/])
TIKA-3869 -- update jackson databind version (tallison:
[https://github.com/apache/tika/commit/e1d9bcd9ae75999078df616c61874cac0a0165e5])
* (edit)
tika-parsers/tika-parsers-standard/tika-parsers-standard-modules/tika-parser-cad-module/pom.xml
* (edit) tika-parent/pom.xml
> Update jackson-databind when available
> --------------------------------------
>
> Key: TIKA-3869
> URL: https://issues.apache.org/jira/browse/TIKA-3869
> Project: Tika
> Issue Type: Task
> Reporter: Tim Allison
> Priority: Minor
> Fix For: 2.5.1
>
>
> No sooner had the 2.5.0 release vote passed than another cve from
> jackson-databind landed in ossindex. For details:
> https://github.com/FasterXML/jackson-databind/issues/3590 and
> https://nvd.nist.gov/vuln/detail/CVE-2022-42003
> We should update jackson-databind when the next non-rc version is available.
> I'll add this to the "ossindex-ignore" list so we can get a clean build for
> now.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)