You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@calcite.apache.org by "Julian Hyde (Jira)" <ji...@apache.org> on 2022/04/26 22:30:00 UTC
[jira] [Resolved] (CALCITE-5115) Upgrade jackson-databind from 2.9.10.1 to 2.13.2.1, and jackson from 2.10.0 to 2.13.2.1
[ https://issues.apache.org/jira/browse/CALCITE-5115?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Julian Hyde resolved CALCITE-5115.
----------------------------------
Resolution: Fixed
Fixed in [c7075f22|https://github.com/apache/calcite/commit/c7075f22b684758cf8de99db4069a3dcd08bd939].
> Upgrade jackson-databind from 2.9.10.1 to 2.13.2.1, and jackson from 2.10.0 to 2.13.2.1
> ---------------------------------------------------------------------------------------
>
> Key: CALCITE-5115
> URL: https://issues.apache.org/jira/browse/CALCITE-5115
> Project: Calcite
> Issue Type: Bug
> Components: core
> Affects Versions: 1.30.0
> Reporter: Florian Brams
> Assignee: Julian Hyde
> Priority: Major
> Labels: pull-request-available
> Fix For: 1.31.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> Upgrading jackson-databind is required to fix [CVE-2020-36518|https://nvd.nist.gov/vuln/detail/CVE-2020-36518]; the fix requires jackson-databind version 2.12.6.1, or 2.13.2.1 or greater.
--
This message was sent by Atlassian Jira
(v8.20.7#820007)