[ 
https://issues.apache.org/jira/browse/HBASE-22778?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16899728#comment-16899728
 ] 

Duo Zhang commented on HBASE-22778:
-----------------------------------

We have purged most of the usage of jackson in hbase, except in the hbase-rest 
module.

But the problem is that, hadoop will pull in a lof jackson related jars...

> Upgrade jasckson databind to 2.9.9.2
> ------------------------------------
>
>                 Key: HBASE-22778
>                 URL: https://issues.apache.org/jira/browse/HBASE-22778
>             Project: HBase
>          Issue Type: Bug
>          Components: dependencies
>            Reporter: Duo Zhang
>            Priority: Blocker
>
> Due to this CVE
> https://nvd.nist.gov/vuln/detail/CVE-2019-14379



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Reply via email to