Преглед на файлове

ZOOKEEPER-4045: CVE-2020-25649 - Upgrade jackson databind to 2.10.5.1

Jackson reported a vulnerability under CVE-2020-25649. Upgrading to 2.10.5.1 will resolve the problem. See https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.10#micro-patches for more details.

Author: Edwin Hobor <edwin.hobor@microfocus.com>

Reviewers: Mate Szalay-Beko <symat@apache.org>, Norbert Kalmar <nkalmar@apache.org>

Closes #1572 from edwin092/ZOOKEEPER-4045
Edwin Hobor преди 4 години
родител
ревизия
676d10b2fa
променени са 1 файла, в които са добавени 1 реда и са изтрити 1 реда
  1. 1 1
      pom.xml

+ 1 - 1
pom.xml

@@ -439,7 +439,7 @@
     <commons-cli.version>1.4</commons-cli.version>
     <netty.version>4.1.50.Final</netty.version>
     <jetty.version>9.4.35.v20201120</jetty.version>
-    <jackson.version>2.10.5</jackson.version>
+    <jackson.version>2.10.5.1</jackson.version>
     <jline.version>2.14.6</jline.version>
     <snappy.version>1.1.7.7</snappy.version>
     <kerby.version>2.0.0</kerby.version>