You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@cassandra.apache.org by "Kevin Eveker (Jira)" <ji...@apache.org> on 2020/05/21 22:08:00 UTC

[jira] [Created] (CASSANDRA-15827) Upgrade to Jackson Databind 2.9.10.4 or later to address CVEs

Kevin Eveker created CASSANDRA-15827:
----------------------------------------

             Summary: Upgrade to Jackson Databind 2.9.10.4 or later to address CVEs
                 Key: CASSANDRA-15827
                 URL: https://issues.apache.org/jira/browse/CASSANDRA-15827
             Project: Cassandra
          Issue Type: Improvement
            Reporter: Kevin Eveker


Recent scan results identified the following CVEs that require this upgrade to address

CVE-2020-8840
CVE-2020-9548
CVE-2020-9547
CVE-2020-9546
CVE-2020-10673
CVE-2020-10672
CVE-2020-10968
CVE-2020-10969
CVE-2020-11112
CVE-2020-11113
CVE-2020-11111
CVE-2020-11619
CVE-2020-11620



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@cassandra.apache.org
For additional commands, e-mail: commits-help@cassandra.apache.org