Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-29226

Upgrade jackson-databind to 2.9.10 and fix vulnerabilities.

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.0.0
    • 3.0.0
    • Build
    • None

    Description

      The current code uses com.fasterxml.jackson.core:jackson-databind:jar:2.9.9.3 and it will cause a security vulnerabilities. We could get some security info fromĀ https://www.tenable.com/cve/CVE-2019-16335

      This reference remind to upgrate the version of `jackson-databind` to 2.9.10 or later.

      Attachments

        Issue Links

          Activity

            People

              beliefer Jiaan Geng
              beliefer Jiaan Geng
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: