[ 
https://issues.apache.org/jira/browse/HBASE-22778?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16901314#comment-16901314
 ] 

Andrew Purtell commented on HBASE-22778:
----------------------------------------

branch-1 is a hard problem because we don't use Jackson 2 (Fasterxml Jackson), 
we use the old Jackson version 1 from when it hosted on Codehaus, in 
hbase-rest, which is in tree in branch-1. This old version of Jackson is also 
pulled in as a transitive dependency of Hadoop and Avro. See HBASE-22728

> Upgrade jasckson databind to 2.9.9.2
> ------------------------------------
>
>                 Key: HBASE-22778
>                 URL: https://issues.apache.org/jira/browse/HBASE-22778
>             Project: HBase
>          Issue Type: Bug
>          Components: dependencies
>            Reporter: Duo Zhang
>            Assignee: niuyulin
>            Priority: Blocker
>             Fix For: 3.0.0, 2.3.0, 2.0.6, 2.2.1, 2.1.6
>
>
> Due to this CVE
> https://nvd.nist.gov/vuln/detail/CVE-2019-14379



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Reply via email to