[ https://issues.apache.org/jira/browse/HDFS-17825?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Alexander Veit updated HDFS-17825: ---------------------------------- Description: {{com.fasterxml.jackson.core:jackson-core:2.12.7}} (from May 2022) which is included in the Apache Hadoop Client Runtime 3.4.2 is affected by CVE-2025-52999 (Score 8.7) and CVE-2025-49128 (Score 4.0). Possible solution: Update to the latest Jackson version. [https://nvd.nist.gov/vuln/detail/CVE-2025-49128] [https://nvd.nist.gov/vuln/detail/CVE-2025-52999] was: {{com.fasterxml.jackson.core:jackson-core:2.12.7}} (from May 2022) which is included in the Apache Hadoop Client Runtime 3.4.2 is affected by CVE-2025-52999 (Score 8.7) and CVE-2025-49128 (Score 4.0). Possible solution: Update to the latest Jackson version. > hadoop-client-runtime vulnerabilities from jackson-core 2.12.7 > -------------------------------------------------------------- > > Key: HDFS-17825 > URL: https://issues.apache.org/jira/browse/HDFS-17825 > Project: Hadoop HDFS > Issue Type: Bug > Affects Versions: 3.4.2 > Reporter: Alexander Veit > Priority: Major > > {{com.fasterxml.jackson.core:jackson-core:2.12.7}} (from May 2022) which is > included in the Apache Hadoop Client Runtime 3.4.2 is affected by > CVE-2025-52999 (Score 8.7) and CVE-2025-49128 (Score 4.0). > Possible solution: Update to the latest Jackson version. > > [https://nvd.nist.gov/vuln/detail/CVE-2025-49128] > [https://nvd.nist.gov/vuln/detail/CVE-2025-52999] > -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: hdfs-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: hdfs-issues-h...@hadoop.apache.org