Skip to content

[LI-HOTFIX] Update jackson-databind from vulnerable version 2.12.3.#317

Merged
wyuka merged 1 commit into
linkedin:3.0-li-dev7from
wyuka:3.0-update-jackson
Mar 24, 2022
Merged

[LI-HOTFIX] Update jackson-databind from vulnerable version 2.12.3.#317
wyuka merged 1 commit into
linkedin:3.0-li-dev7from
wyuka:3.0-update-jackson

Conversation

@wyuka

@wyuka wyuka commented Mar 24, 2022

Copy link
Copy Markdown

com.fasterxml.jackson.core:jackson-databind:2.12.3 is vulnerable to denial of service. A malicious user is able to cause a StackOverflow exception using a large depth of nested objects resulting in a denial of service conditions.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36518

Committer Checklist (excluded from commit message)

  • Verify design and implementation
  • Verify test coverage and CI build status
  • Verify documentation (including upgrade notes)

@wyuka
wyuka requested a review from sutambe March 24, 2022 20:17
@wyuka wyuka changed the title Update jackson-databind from vulnerable version 2.12.3. [LI-HOTFIX] Update jackson-databind from vulnerable version 2.12.3. Mar 24, 2022
@wyuka
wyuka requested a review from gitlw March 24, 2022 20:19
@wyuka
wyuka merged commit 0d5c730 into linkedin:3.0-li-dev7 Mar 24, 2022
lmr3796 pushed a commit to lmr3796/kafka that referenced this pull request Mar 25, 2022
…#317)

TICKET =
LI_DESCRIPTION = com.fasterxml.jackson.core:jackson-databind:2.12.3 is vulnerable to denial of service. A malicious user is able to cause a StackOverflow exception using a large depth of nested objects resulting in a denial of service conditions.
EXIT_CRITERIA = "When the dependency is bumped to 2.14 or higher"
lmr3796 pushed a commit to lmr3796/kafka that referenced this pull request Mar 31, 2022
This should effectively purge LI commit
- [LI-HOTFIX] Update jackson-databind from vulnerable version (linkedin#317)

== Original upstream commit message ==

KAFKA-13775: CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1 (apache#11962)

CVE-2020-36518 vulnerability affects jackson-databind (see GHSA-57j2-w4cx-62h2).

Upgrading to jackson-databind version 2.12.6.1 addresses this CVE.

Reviewers: Luke Chen <showuon@gmail.com>, Bruno Cadonna <cadonna@apache.org>
lmr3796 added a commit to lmr3796/kafka that referenced this pull request Mar 31, 2022
This should effectively purge LI commit
- [LI-HOTFIX] Update jackson-databind from vulnerable version (linkedin#317)

== Original upstream commit [76ca62a] ==

KAFKA-13775: CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1 (apache#11962)

CVE-2020-36518 vulnerability affects jackson-databind (see GHSA-57j2-w4cx-62h2).

Upgrading to jackson-databind version 2.12.6.1 addresses this CVE.

Reviewers: Luke Chen <showuon@gmail.com>, Bruno Cadonna <cadonna@apache.org>

Co-authored-by: Edwin <edwinhobor@gmail.com>
lmr3796 pushed a commit to lmr3796/kafka that referenced this pull request Jun 2, 2022
…#317)

TICKET =
LI_DESCRIPTION = com.fasterxml.jackson.core:jackson-databind:2.12.3 is vulnerable to denial of service. A malicious user is able to cause a StackOverflow exception using a large depth of nested objects resulting in a denial of service conditions.
EXIT_CRITERIA = "When the dependency is bumped to 2.14 or higher"
lmr3796 added a commit to lmr3796/kafka that referenced this pull request Jun 2, 2022
This should effectively purge LI commit
- [LI-HOTFIX] Update jackson-databind from vulnerable version (linkedin#317)

== Original upstream commit [76ca62a] ==

KAFKA-13775: CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1 (apache#11962)

CVE-2020-36518 vulnerability affects jackson-databind (see GHSA-57j2-w4cx-62h2).

Upgrading to jackson-databind version 2.12.6.1 addresses this CVE.

Reviewers: Luke Chen <showuon@gmail.com>, Bruno Cadonna <cadonna@apache.org>

Co-authored-by: Edwin <edwinhobor@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants