Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple Critical/High severity CVE's in the version of Jackson Databind #109

Open
jswingle-git opened this issue Jul 20, 2021 · 3 comments
Labels

Comments

@jswingle-git jswingle-git changed the title Multiple Critical/High severity CVE Multiple Critical/High severity CVE's in the version of Jackson Databind Jul 20, 2021
@tronda
Copy link

tronda commented Apr 3, 2023

jackson-databind is used by Spark. In order to get this dependency to a version without CVE's the dependecy need to be bumped to latest in version 3.3.X or 3.2.X. I've tried to upgrade to the latest version of Spark, but then I get a compilation error on flatMapValues method which seems to have changed the signature. I have no knowledge of Spark so not sure what the best approach forward is here.

@tronda
Copy link

tronda commented Nov 10, 2023

We have overridden the Jackson dependencies and created a custom docker container which we are using internally. Addresses the critical vulnerabilities:
https://github.com/DIPSAS/spark-dependencies

@ruospalo
Copy link
Contributor

ruospalo commented Mar 6, 2024

I've created #135 that bumped spark to the latest version and fixes all the above CVEs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants