Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-28073

Upgrade jackson version to 2.16.1

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 4.0.0
    • None

    Description

      Jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies.
      https://nvd.nist.gov/vuln/detail/CVE-2023-35116
      https://github.com/FasterXML/jackson-databind/issues/3972

      Attachments

        Issue Links

          Activity

            People

              araika Araika Singh
              araika Araika Singh
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: