You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tika.apache.org by "Hudson (Jira)" <ji...@apache.org> on 2022/10/03 20:13:00 UTC

[jira] [Commented] (TIKA-3869) Update jackson-databind when available

    [ https://issues.apache.org/jira/browse/TIKA-3869?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17612427#comment-17612427 ] 

Hudson commented on TIKA-3869:
------------------------------

SUCCESS: Integrated in Jenkins build Tika ยป tika-main-jdk8 #827 (See [https://ci-builds.apache.org/job/Tika/job/tika-main-jdk8/827/])
TIKA-3869 -- ignore ossindex on databind for now (tallison: [https://github.com/apache/tika/commit/96df8d9897ca0525bd5fc89e32b0c9477ed73b03])
* (edit) tika-parent/pom.xml


> Update jackson-databind when available
> --------------------------------------
>
>                 Key: TIKA-3869
>                 URL: https://issues.apache.org/jira/browse/TIKA-3869
>             Project: Tika
>          Issue Type: Task
>            Reporter: Tim Allison
>            Priority: Minor
>
> No sooner had the 2.5.0 release vote passed than another cve from jackson-databind landed in ossindex.  For details: https://github.com/FasterXML/jackson-databind/issues/3590 and https://nvd.nist.gov/vuln/detail/CVE-2022-42003
> We should update jackson-databind when the next non-rc version is available.
> I'll add this to the "ossindex-ignore" list so we can get a clean build for now.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)