You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@flume.apache.org by GitBox <gi...@apache.org> on 2020/05/20 10:23:33 UTC

[GitHub] [flume] wcc526 opened a new pull request #327: Jackson has a serious security problem in 2.9.7, which will cause RCE

wcc526 opened a new pull request #327:
URL: https://github.com/apache/flume/pull/327


   https://github.com/FasterXML/jackson-databind/issues/2295


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flume] tmgstevens commented on pull request #327: Jackson has a serious security problem in 2.9.7, which will cause RCE

Posted by GitBox <gi...@apache.org>.
tmgstevens commented on pull request #327:
URL: https://github.com/apache/flume/pull/327#issuecomment-631480170


   I've just tried building this and get the following:
   `[ERROR] Failed to execute goal on project flume-hdfs-sink: Could not resolve dependencies for project org.apache.flume.flume-ng-sinks:flume-hdfs-sink:jar:1.10.0-SNAPSHOT: The following artifacts could not be resolved: com.fasterxml.jackson.core:jackson-annotations:jar:2.9.10.3, com.fasterxml.jackson.core:jackson-core:jar:2.9.10.3: Could not find artifact com.fasterxml.jackson.core:jackson-annotations:jar:2.9.10.3 in central (https://repo.maven.apache.org/maven2)`


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flume] bessbd commented on pull request #327: Jackson has a serious security problem in 2.9.7, which will cause RCE

Posted by GitBox <gi...@apache.org>.
bessbd commented on pull request #327:
URL: https://github.com/apache/flume/pull/327#issuecomment-632331961


   @wcc526, thank you for the patch!
   @tmgstevens, thank you for the merge!


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flume] wcc526 commented on pull request #327: Jackson has a serious security problem in 2.9.7, which will cause RCE

Posted by GitBox <gi...@apache.org>.
wcc526 commented on pull request #327:
URL: https://github.com/apache/flume/pull/327#issuecomment-631818617


   sorry ,the new version is 2.9.10,I have modified it 


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [flume] tmgstevens merged pull request #327: Jackson has a serious security problem in 2.9.7, which will cause RCE

Posted by GitBox <gi...@apache.org>.
tmgstevens merged pull request #327:
URL: https://github.com/apache/flume/pull/327


   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org