[ 
https://issues.apache.org/jira/browse/KAFKA-13658?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17499589#comment-17499589
 ] 

Pratim Chaudhuri commented on KAFKA-13658:
------------------------------------------

[~cadonna]  [~showuon] 

Looks like the fix was implemented as part of the pull request : 
[https://github.com/apache/kafka/pull/11656]

The jackson module has been updated to v2.12.6, which has fix for the reported 
vulnerability. 

Ref: [https://github.com/FasterXML/jackson-databind/issues/3328] 

I did not go ahead with the initial proposal to increase the version of 
Jacksion to 2.13.1 , which also has the fix.

> Upgrade vulnerable dependencies jan 2022
> ----------------------------------------
>
>                 Key: KAFKA-13658
>                 URL: https://issues.apache.org/jira/browse/KAFKA-13658
>             Project: Kafka
>          Issue Type: Bug
>    Affects Versions: 2.8.1
>            Reporter: Shivakumar
>            Priority: Major
>              Labels: secutiry
>
> |Packages|Package Version|CVSS|Fix Status|
> |com.fasterxml.jackson.core_jackson-databind| 2.10.5.1| 7.5| fixed in 2.14, 
> 2.13.1, 2.12.6|
> | | | | |
> Our security scan detected the above vulnerabilities
> upgrade to correct versions for fixing vulnerabilities



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to