Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability found in org.codehaus.jackson:jackson-mapper-asl #120

Open
schubon opened this issue Feb 5, 2020 · 4 comments
Open

Vulnerability found in org.codehaus.jackson:jackson-mapper-asl #120

schubon opened this issue Feb 5, 2020 · 4 comments
Labels

Comments

@schubon
Copy link
Member

schubon commented Feb 5, 2020

Details

CVE-2019-10172

moderate severity
Vulnerable versions: <= 1.9.13
Patched version: No fix

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar to CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

Remediation

No patched version is available.

@schubon schubon added the bug label Feb 5, 2020
@anouri
Copy link
Member

anouri commented Feb 5, 2020

The latest version of jackson-core-asl and ackson-mapper-asl libraries are 1.9.13 and they are from 2013.
There has been no further releases since then.

Hadoop and HBase uses these libraries also in the newest released version 3.1 from Nov. 2019.

/usr/hdp/3.1.0.0-78/hbase/lib/jackson-core-asl-1.9.13.jar
/usr/hdp/3.1.0.0-78/hbase/lib/jackson-mapper-asl-1.9.13.jar
/usr/hdp/3.1.0.0-78/hadoop/lib/jackson-core-asl-1.9.13.jar
/usr/hdp/3.1.0.0-78/hadoop/lib/jackson-mapper-asl-1.9.13.jar

@anouri
Copy link
Member

anouri commented Apr 2, 2020

Correction delivered in version streamsx.hdfs 5.2.0
https://github.com/IBMStreams/streamsx.hdfs/releases/tag/v5.2.0

@anouri anouri closed this as completed Apr 6, 2020
@xuzikun2003
Copy link

Why is this issue closed? It looks like we don't have a fix for this vulnerability yet.

@schubon
Copy link
Member Author

schubon commented May 10, 2021

I have to agree @xuzikun2003, as there are no new versions of the libraries showing the vulnerability, it cannot be corrected.

@schubon schubon reopened this May 10, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants