You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@ignite.apache.org by "Igor Baryshnikov (Jira)" <ji...@apache.org> on 2021/01/25 18:16:00 UTC

[jira] [Assigned] (IGNITE-13601) Ignite-rest-http and ignite-kubernetes include vulnerable dependencies

     [ https://issues.apache.org/jira/browse/IGNITE-13601?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Igor Baryshnikov reassigned IGNITE-13601:
-----------------------------------------

    Assignee: Igor Baryshnikov

> Ignite-rest-http and ignite-kubernetes include vulnerable dependencies
> ----------------------------------------------------------------------
>
>                 Key: IGNITE-13601
>                 URL: https://issues.apache.org/jira/browse/IGNITE-13601
>             Project: Ignite
>          Issue Type: Bug
>          Components: rest
>    Affects Versions: 2.8.1
>            Reporter: Andrew Story
>            Assignee: Igor Baryshnikov
>            Priority: Blocker
>              Labels: 2.9.1-rc
>
> The ignite-rest-http and ignite-kubernetes modules include a vulnerable version of the jackson-databind library. This was spotted in 2.8.1.
> This component jackson-databind-2.9.6.jar is flagged as having numerous 
> critical, high and medium security vulnerabilities, one of which is 
> described here: 
> [https://nvd.nist.gov/vuln/detail/CVE-2019-14540]
> More here:
> [http://apache-ignite-users.70518.x6.nabble.com/Critical-security-vulnerability-for-opt-ignite-apache-ignite-libs-optional-ignite-rest-http-jackson-r-td34032.html]
>  



--
This message was sent by Atlassian Jira
(v8.3.4#803005)