Skip to content

Commit

Permalink
[fix][security] Upgrade jackson and jackson-databind (2.13.2.1) to ge…
Browse files Browse the repository at this point in the history
…t rid of CVE-2020-36518 (#14871)

* [fix][security] Upgrade JacksonXML to get rid of CVE-2020-36518

* force jackson-databind version
  • Loading branch information
nicoloboschi committed Mar 28, 2022
1 parent d03e2d3 commit 6d9ba7b
Show file tree
Hide file tree
Showing 6 changed files with 31 additions and 28 deletions.
16 changes: 8 additions & 8 deletions distribution/server/src/assemble/LICENSE.bin.txt
Expand Up @@ -312,14 +312,14 @@ The Apache Software License, Version 2.0
* JCommander -- com.beust-jcommander-1.78.jar
* High Performance Primitive Collections for Java -- com.carrotsearch-hppc-0.7.3.jar
* Jackson
- com.fasterxml.jackson.core-jackson-annotations-2.12.6.jar
- com.fasterxml.jackson.core-jackson-core-2.12.6.jar
- com.fasterxml.jackson.core-jackson-databind-2.12.6.jar
- com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.12.6.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.12.6.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.12.6.jar
- com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.12.6.jar
- com.fasterxml.jackson.module-jackson-module-jsonSchema-2.12.6.jar
- com.fasterxml.jackson.core-jackson-annotations-2.13.2.jar
- com.fasterxml.jackson.core-jackson-core-2.13.2.jar
- com.fasterxml.jackson.core-jackson-databind-2.13.2.1.jar
- com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.13.2.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.13.2.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.13.2.jar
- com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.13.2.jar
- com.fasterxml.jackson.module-jackson-module-jsonSchema-2.13.2.jar
* Caffeine -- com.github.ben-manes.caffeine-caffeine-2.9.1.jar
* Conscrypt -- org.conscrypt-conscrypt-openjdk-uber-2.5.2.jar
* Proto Google Common Protos -- com.google.api.grpc-proto-google-common-protos-2.0.1.jar
Expand Down
9 changes: 7 additions & 2 deletions pom.xml
Expand Up @@ -124,8 +124,8 @@ flexible messaging model and an intuitive client API.</description>
<log4j2.version>2.17.1</log4j2.version>
<bouncycastle.version>1.69</bouncycastle.version>
<bouncycastlefips.version>1.0.2</bouncycastlefips.version>
<jackson.version>2.12.6</jackson.version>
<jackson.databind.version>2.12.6</jackson.databind.version>
<jackson.version>2.13.2</jackson.version>
<jackson.databind.version>2.13.2.1</jackson.databind.version>
<reflections.version>0.9.11</reflections.version>
<swagger.version>1.6.2</swagger.version>
<puppycrawl.checkstyle.version>8.37</puppycrawl.checkstyle.version>
Expand Down Expand Up @@ -782,6 +782,11 @@ flexible messaging model and an intuitive client API.</description>
<type>pom</type>
<scope>import</scope>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson.databind.version}</version>
</dependency>

<dependency>
<artifactId>log4j</artifactId>
Expand Down
1 change: 0 additions & 1 deletion pulsar-functions/runtime-all/pom.xml
Expand Up @@ -76,7 +76,6 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson.databind.version}</version>
</dependency>

<!--In order to support protobuf schema, this dependency needs to be added-->
Expand Down
1 change: 0 additions & 1 deletion pulsar-io/elastic-search/pom.xml
Expand Up @@ -60,7 +60,6 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson.databind.version}</version>
</dependency>

<dependency>
Expand Down
28 changes: 14 additions & 14 deletions pulsar-sql/presto-distribution/LICENSE
Expand Up @@ -207,19 +207,19 @@ This projects includes binary packages with the following licenses:
The Apache Software License, Version 2.0

* Jackson
- jackson-annotations-2.12.6.jar
- jackson-core-2.12.6.jar
- jackson-databind-2.12.6.jar
- jackson-dataformat-smile-2.12.6.jar
- jackson-datatype-guava-2.12.6.jar
- jackson-datatype-jdk8-2.12.6.jar
- jackson-datatype-joda-2.12.6.jar
- jackson-datatype-jsr310-2.12.6.jar
- jackson-dataformat-yaml-2.12.6.jar
- jackson-jaxrs-base-2.12.6.jar
- jackson-jaxrs-json-provider-2.12.6.jar
- jackson-module-jaxb-annotations-2.12.6.jar
- jackson-module-jsonSchema-2.12.6.jar
- jackson-annotations-2.13.2.jar
- jackson-core-2.13.2.jar
- jackson-databind-2.13.2.1.jar
- jackson-dataformat-smile-2.13.2.jar
- jackson-datatype-guava-2.13.2.jar
- jackson-datatype-jdk8-2.13.2.jar
- jackson-datatype-joda-2.13.2.jar
- jackson-datatype-jsr310-2.13.2.jar
- jackson-dataformat-yaml-2.13.2.jar
- jackson-jaxrs-base-2.13.2.jar
- jackson-jaxrs-json-provider-2.13.2.jar
- jackson-module-jaxb-annotations-2.13.2.jar
- jackson-module-jsonSchema-2.13.2.jar
* Guava
- guava-31.0.1-jre.jar
- listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
Expand Down Expand Up @@ -454,7 +454,7 @@ The Apache Software License, Version 2.0
* Snappy
- snappy-java-1.1.7.jar
* Jackson
- jackson-module-parameter-names-2.12.6.jar
- jackson-module-parameter-names-2.13.2.jar
* Java Assist
- javassist-3.25.0-GA.jar
* Java Native Access
Expand Down
4 changes: 2 additions & 2 deletions pulsar-sql/presto-distribution/pom.xml
Expand Up @@ -38,10 +38,10 @@
<airlift.version>0.170</airlift.version>
<objenesis.version>2.6</objenesis.version>
<objectsize.version>0.0.12</objectsize.version>
<jackson.version>2.12.6</jackson.version>
<jackson.version>2.13.2</jackson.version>
<!--fix Security Vulnerabilities-->
<!--https://www.cvedetails.com/vulnerability-list/vendor_id-15866/product_id-42991/Fasterxml-Jackson-databind.html-->
<jackson.databind.version>2.12.6</jackson.databind.version>
<jackson.databind.version>2.13.2.1</jackson.databind.version>
<maven.version>3.0.5</maven.version>
<guava.version>31.0.1-jre</guava.version>
<asynchttpclient.version>2.12.1</asynchttpclient.version>
Expand Down

0 comments on commit 6d9ba7b

Please sign in to comment.