Browse Source

ZOOKEEPER-3405: Upgrade the version of Jackson-databind to address OWASP CVE

Upgraded the library to the latest version.

Change-Id: I94743e7f7817202fff25c757730ba05fe0a9cc17

Author: Patrick Hunt <phunt@apache.org>

Reviewers: Enrico Olivelli <eolivelli@apache.org>, Norbert Kalmar <nkalmar@apache.org>

Closes #962 from phunt/ZOOKEEPER-3405
Patrick Hunt 6 năm trước cách đây
mục cha
commit
ca4b12430e
2 tập tin đã thay đổi với 2 bổ sung2 xóa
  1. 1 1
      build.xml
  2. 1 1
      pom.xml

+ 1 - 1
build.xml

@@ -55,7 +55,7 @@ xmlns:cs="antlib:com.puppycrawl.tools.checkstyle.ant">
     <property name="javacc.version" value="5.0"/>
 
     <property name="jetty.version" value="9.4.15.v20190215"/>
-    <property name="jackson.version" value="2.9.8"/>
+    <property name="jackson.version" value="2.9.9"/>
     <property name="dependency-check-ant.version" value="4.0.2"/>
 
     <property name="commons-io.version" value="2.6"/>

+ 1 - 1
pom.xml

@@ -279,7 +279,7 @@
     <commons-cli.version>1.2</commons-cli.version>
     <netty.version>4.1.29.Final</netty.version>
     <jetty.version>9.4.17.v20190418</jetty.version>
-    <jackson.version>2.9.8</jackson.version>
+    <jackson.version>2.9.9</jackson.version>
     <json.version>1.1.1</json.version>
     <jline.version>2.11</jline.version>
     <snappy.version>1.1.7</snappy.version>