[
https://issues.apache.org/jira/browse/HBASE-30282?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Nihal Jain updated HBASE-30282:
-------------------------------
Hadoop Flags: Reviewed
> [hbase-thirdparty] Bump jackson-jaxrs-json-provider to 2.22.3
>
> ------------------------------------------------------------------------------------------------------
>
> Key: HBASE-30282
> URL: https://issues.apache.org/jira/browse/HBASE-30282
> Project: HBase
> Issue Type: Task
> Components: security, thirdparty
> Affects Versions: thirdparty-4.1.14
> Reporter: Xavier Fernandis
> Assignee: Xavier Fernandis
> Priority: Major
> Labels: pull-request-available
> Fix For: thirdparty-4.1.15
>
>
> Upgrade jackson-jaxrs-json-provider from 2.21.1 to 2.22.3 to pull in security
> fixes for jackson-databind and jackson-core.
>
> *CVE fixes due to this upgrade :*
> CVE-2026-54512
> CVE-2026-54513
> CVE-2026-54514
> CVE-2026-54515
> CVE-2026-54516
> CVE-2026-54517
> CVE-2026-54518
> CVE-2026-59888
> CVE-2026-59889
> CVE-2026-77310
> CVE-2026-68497
> CVE-2026-19032
> CVE-2026-83557
> CVE-2026-91776
> CVE-2026-91777
> CVE-2026-68498
> CVE-2026-89407
> CVE-2026-89425
> *HBase compatibility assessment*
> Binary / source compatibility
> * Public API diff of the shipped jars (jackson-core, jackson-databind,
> jackson-annotations) shows zero public API removals or signature changes. The
> only differences are internal, version-stamped classes and internal
> deserializer helper fields. The upgrade is binary- and source-compatible; no
> HBase code requires modification.
> Behavioral compatibility
> * The behavior-affecting changes in 2.22.x are all security hardening of
> polymorphic / default typing (@JsonTypeInfo,
> activateDefaultTyping), InetAddress/Path/InetSocketAddress deserialization,
> and stream-size limits.
> * HBase enables none of these code paths. A grep across all active
> apache/hbase branches (master, branch-3, branch-2, branch-2.6, branch-2.5)
> returns zero uses of @JsonTypeInfo, activateDefaultTyping,
> enableDefaultTyping, PolymorphicTypeValidator, or DefaultTyping.
> *Conclusion*
> * Upgrade value for HBase is CVE remediation only; functional and
> compatibility impact is none. No source changes required beyond keeping
> jackson.version in HBase in sync with the jaxrs-json-provider shipped by
> hbase-thirdparty.
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)