[ 
https://issues.apache.org/jira/browse/BEAM-7881?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16989414#comment-16989414
 ] 

Romain Manni-Bucau commented on BEAM-7881:
------------------------------------------

I will just highlight that the 0day issue was due to the presence of jars, not 
their feature activation and that beam does not own jackson version but the 
runner does. So best beam can do is to decoralate itself from such libs IMHO.

Now if the community does not care, please just close the ticket, this is no 
more a blocker for me.

> Get rid of jackson to avoid the continuous flow of CVEs in Jackson
> ------------------------------------------------------------------
>
>                 Key: BEAM-7881
>                 URL: https://issues.apache.org/jira/browse/BEAM-7881
>             Project: Beam
>          Issue Type: Task
>          Components: sdk-java-core
>    Affects Versions: 2.14.0
>            Reporter: Romain Manni-Bucau
>            Priority: Blocker
>
> Jackson keeps having CVE on all releases of databind and transitively beam 
> sdk java core has CVE on all its releases (for the record, when writing this 
> issue you must use at least jackson-databind 2.9.9.2 but last week it was 
> 2.9.9.1 and 2.14 didn't get the fix).
> Can be neat to get rid of jackson which does not fix this issue for a very 
> long time now and just use JSON-B or another JSON impl to ensure the CVE is 
> not usable because beam is there.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to