You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
moderate severity
Vulnerable versions: <= 1.9.13
Patched version: No fix
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar to CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
Remediation
No patched version is available.
The text was updated successfully, but these errors were encountered:
The latest version of jackson-core-asl and ackson-mapper-asl libraries are 1.9.13 and they are from 2013.
There has been no further releases since then.
Hadoop and HBase uses these libraries also in the newest released version 3.1 from Nov. 2019.
Details
CVE-2019-10172
moderate severity
Vulnerable versions: <= 1.9.13
Patched version: No fix
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar to CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
Remediation
No patched version is available.
The text was updated successfully, but these errors were encountered: