[ 
https://issues.apache.org/jira/browse/HBASE-30282?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Nihal Jain updated HBASE-30282:
-------------------------------
    Hadoop Flags: Reviewed

> [hbase-thirdparty] Bump jackson-jaxrs-json-provider to 2.22.3                 
>                         
> ------------------------------------------------------------------------------------------------------
>
>                 Key: HBASE-30282
>                 URL: https://issues.apache.org/jira/browse/HBASE-30282
>             Project: HBase
>          Issue Type: Task
>          Components: security, thirdparty
>    Affects Versions: thirdparty-4.1.14
>            Reporter: Xavier Fernandis
>            Assignee: Xavier Fernandis
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: thirdparty-4.1.15
>
>
> Upgrade jackson-jaxrs-json-provider from 2.21.1 to 2.22.3 to pull in security 
> fixes for  jackson-databind and jackson-core. 
>  
> *CVE fixes due to this upgrade :* 
> CVE-2026-54512
>   CVE-2026-54513
>   CVE-2026-54514
>   CVE-2026-54515
>   CVE-2026-54516
>   CVE-2026-54517
>   CVE-2026-54518
>   CVE-2026-59888
>   CVE-2026-59889
>   CVE-2026-77310
>   CVE-2026-68497
>   CVE-2026-19032
>   CVE-2026-83557
>   CVE-2026-91776
>   CVE-2026-91777
>   CVE-2026-68498
>   CVE-2026-89407
>   CVE-2026-89425
> *HBase compatibility assessment*
> Binary / source compatibility
>  * Public API diff of the shipped jars (jackson-core, jackson-databind, 
> jackson-annotations) shows zero public API removals or signature changes. The 
> only differences are internal, version-stamped classes and internal 
> deserializer helper fields. The upgrade is binary- and source-compatible; no 
> HBase code requires modification.
> Behavioral compatibility
>  * The behavior-affecting changes in 2.22.x are all security hardening of 
> polymorphic / default typing (@JsonTypeInfo,
> activateDefaultTyping), InetAddress/Path/InetSocketAddress deserialization, 
> and stream-size limits.
>  * HBase enables none of these code paths. A grep across all active 
> apache/hbase branches (master, branch-3, branch-2, branch-2.6, branch-2.5) 
> returns zero uses of @JsonTypeInfo, activateDefaultTyping, 
> enableDefaultTyping, PolymorphicTypeValidator, or DefaultTyping.
> *Conclusion*
>  * Upgrade value for HBase is CVE remediation only; functional and 
> compatibility impact is none. No source changes required beyond keeping 
> jackson.version in HBase in sync with the jaxrs-json-provider shipped by 
> hbase-thirdparty.
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to