LuciferYang commented on pull request #30746:
URL: https://github.com/apache/spark/pull/30746#issuecomment-760686077


   ```
   FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction 
between serialization gadgets and typing, related to 
oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
   ```
   
   
[CVE-2020-36179](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36179)
   
   I found Spark 2.4 still using Jackson 2.6.7
   
   
https://github.com/apache/spark/blob/63e93a5c38a83669ccc58a5b45d5cff0b296fcc9/pom.xml#L161-L163
   
   Should we upgrade it and which version should we use in Spark 2.4.
   
   cc @wangyum @dongjoon-hyun @HyukjinKwon 


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to