[ https://issues.apache.org/jira/browse/STORM-3820?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
PJ Fanning closed STORM-3820. ----------------------------- Resolution: Fixed looks like this was resolved > storm uses jackson version that has a security issue (entity expansion) > ----------------------------------------------------------------------- > > Key: STORM-3820 > URL: https://issues.apache.org/jira/browse/STORM-3820 > Project: Apache Storm > Issue Type: Dependency upgrade > Reporter: PJ Fanning > Priority: Major > Time Spent: 2h > Remaining Estimate: 0h > > [https://github.com/apache/storm/blob/master/pom.xml#L342] (v2.10.0) > [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25649] > Using v2.10.5.1 will fix this issue with fewer risks than upgrading jackson > to 2.13.x. -- This message was sent by Atlassian Jira (v8.20.10#820010)