-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2020-36518] Update jackson-databind to 2.13.2.1 #2597
Comments
Looks like the 2.13.2 change never made it to 1.3, this is causing issues since security picked up this change. |
@reta looks the team is working on 1.3.2 release and Security plugin, OpenSearch have different versions for jackson-databind. |
@saratvemulapalli yes, the 2.12.6.1 had a CVE fix we needed to address. The 1.3 release line uses Jackson 2.12.6, we could update to 2.13.x but AFAIK the minor releases only include bugfixes (2.13.2.2 should have same CVE fix as 2.12.6.1).
|
@zelinh I am going to confirm we can take the patch version into security as @reta suggests. I've created this issue to resolve the root cause: opensearch-project/security#1816 |
#1817 has been merged. Closing this. |
Describe the bug
jackson-databind
up to 2.13.2 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.[1] https://nvd.nist.gov/vuln/detail/CVE-2020-36518
[2] FasterXML/jackson-databind#2816
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Update
jackson-databind
to 2.13.2.1Plugins
Please list all plugins currently enabled.
Screenshots
If applicable, add screenshots to help explain your problem.
Host/Environment (please complete the following information):
Additional context
Add any other context about the problem here.
The text was updated successfully, but these errors were encountered: