-
Notifications
You must be signed in to change notification settings - Fork 260
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability Reported in jackson-databind 2.6 #151
Comments
Information on the vulnerability says it is fixed in 2.6.7.1 and 2.8.9, among other versions of Jackson. |
@randallwhitman when making this change we also should remove DepFiles folder with the jar files from the repo. |
@randallwhitman Should we fix this as well for the next release? |
Yes, when we make a release, let's definitely include this. |
@randallwhitman Please, review my pull request. As a warning, people who relied on ant build would have to copy the jars manually. |
@alocke Could you verify this? |
Yes, I will. |
Thank you Annette! |
An issue was filed today on Spatial Framework for Hadoop regarding a vulnerability in jackson-databind 2.6 version - Esri/spatial-framework-for-hadoop#146.
In order to use a new Jackson version, Spatial Framework needs the Geometry API to be compatible with a suitable newer version of Jackson.
The text was updated successfully, but these errors were encountered: