Skip to content

[LI-CHERRY-PICK] Bump vulnerable jackson-databind#327

Merged
lmr3796 merged 1 commit into
linkedin:3.0-li-rc1from
lmr3796:3.0-li-rc1
Mar 31, 2022
Merged

[LI-CHERRY-PICK] Bump vulnerable jackson-databind#327
lmr3796 merged 1 commit into
linkedin:3.0-li-rc1from
lmr3796:3.0-li-rc1

Conversation

@lmr3796

@lmr3796 lmr3796 commented Mar 31, 2022

Copy link
Copy Markdown

This should effectively purge LI commit

== Original upstream commit [76ca62a] ==

KAFKA-13775: CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1 (apache#11962)

CVE-2020-36518 vulnerability affects jackson-databind (see GHSA-57j2-w4cx-62h2).

Upgrading to jackson-databind version 2.12.6.1 addresses this CVE.

Reviewers: Luke Chen showuon@gmail.com, Bruno Cadonna cadonna@apache.org

More detailed description of your change,
if necessary. The PR title and PR message become
the squashed commit message, so use a separate
comment to ping reviewers.

Summary of testing strategy (including rationale)
for the feature or bug fix. Unit and/or integration
tests are expected for any behaviour change and
system tests should be considered for larger changes.

Committer Checklist (excluded from commit message)

  • Verify design and implementation
  • Verify test coverage and CI build status
  • Verify documentation (including upgrade notes)

This should effectively purge LI commit
- [LI-HOTFIX] Update jackson-databind from vulnerable version (linkedin#317)

== Original upstream commit message ==

KAFKA-13775: CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1 (apache#11962)

CVE-2020-36518 vulnerability affects jackson-databind (see GHSA-57j2-w4cx-62h2).

Upgrading to jackson-databind version 2.12.6.1 addresses this CVE.

Reviewers: Luke Chen <showuon@gmail.com>, Bruno Cadonna <cadonna@apache.org>
@lmr3796 lmr3796 requested a review from wyuka March 31, 2022 02:57
@lmr3796 lmr3796 merged commit d517469 into linkedin:3.0-li-rc1 Mar 31, 2022
lmr3796 added a commit to lmr3796/kafka that referenced this pull request Jun 2, 2022
This should effectively purge LI commit
- [LI-HOTFIX] Update jackson-databind from vulnerable version (linkedin#317)

== Original upstream commit [76ca62a] ==

KAFKA-13775: CVE-2020-36518 - Upgrade jackson-databind to 2.12.6.1 (apache#11962)

CVE-2020-36518 vulnerability affects jackson-databind (see GHSA-57j2-w4cx-62h2).

Upgrading to jackson-databind version 2.12.6.1 addresses this CVE.

Reviewers: Luke Chen <showuon@gmail.com>, Bruno Cadonna <cadonna@apache.org>

Co-authored-by: Edwin <edwinhobor@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants