[ovirt-devel] Re: Jackson-databind related changes

2023-09-15 Thread Martin Perina
Hi, oVirt Engine is using JBoss Modules feature to load libraries, so when a library version is mentioned in pom.xml it's unrelated to which version is being using during runtime. Here's the detailed description: 1. jackson-databind 2.12.7 mentioned pom.xml is actually being used only when buildi

[ovirt-devel] Re: Jackson-databind related changes

2023-09-15 Thread Sandro Bonazzola
@Martin Perina can you help here? Il giorno gio 14 set 2023 alle ore 23:44 Shubha Kulkarni < shubha.kulka...@oracle.com> ha scritto: > Hi All > > > > I am yet to get any feedback on my query. So I thought I will reach out > again to see if any one has comment on this - > > > > Background: > > I

[ovirt-devel] Re: Jackson-databind related changes

2023-09-14 Thread Shubha Kulkarni
Hi All I am yet to get any feedback on my query. So I thought I will reach out again to see if any one has comment on this - Background: I see the commit for CVE-2020-36518 to vdsm-json-rpc to bump jackson version to 2.12.7 https://github.com/oVirt/vdsm-jsonrpc-java/commit/d1f423809fd491da7b532