[ 
https://issues.apache.org/jira/browse/HBASE-22728?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16893959#comment-16893959
 ] 

Andrew Purtell commented on HBASE-22728:
----------------------------------------

Yes I think it would help. Aside from where we declare it a dependency 
ourselves in server it comes in from Hadoop and Avro. Curious if Avro is still 
functional if we exclude Jackson. Otherwise, rest uses it, but it’s been moved 
out in later versions and for branch-1 we can take the occasion of a minor to 
port back the code using Jackson 2 and safe versions. 

> Upgrade jackson dependencies in branch-1
> ----------------------------------------
>
>                 Key: HBASE-22728
>                 URL: https://issues.apache.org/jira/browse/HBASE-22728
>             Project: HBase
>          Issue Type: Sub-task
>    Affects Versions: 1.4.10, 1.3.5
>            Reporter: Andrew Purtell
>            Priority: Major
>             Fix For: 1.5.0, 1.3.6, 1.4.11
>
>
> Avoid Jackson versions and dependencies with known CVEs



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Reply via email to