Skip to content

security vulnerabilities in 3rd party dependencies #1767

@sijie

Description

@sijie

Similar as apache/pulsar#2882, bookkeeper has 3rd party dependencies that are exposed to security vulnerabilities

mvn com.redhat.victims.maven:security-versions:check

Results:

[ERROR] jline:jline is vulnerable to CVE-2013-2035
[ERROR] com.fasterxml.jackson.core:jackson-databind is vulnerable to CVE-2017-17485
[ERROR] com.fasterxml.jackson.core:jackson-databind is vulnerable to CVE-2017-7525
[ERROR] com.fasterxml.jackson.core:jackson-databind is vulnerable to CVE-2018-5968

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions