-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Open
Labels
LibrariesLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respoLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respobugSomething isn't workingSomething isn't working
Description
Describe the bug
1.3.x is currently using Jackson 2.14.2. Jackson 2.14.2 is affected by https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538.
Bumping to 2.15.0+ would help with addressing issues raised by security scanners that consider OpenSearch 1.3.x as affected.
Related component
Libraries
To Reproduce
Check Jackson version on the latest 1.3 branch.
Expected behavior
1.3.x is using Jackson 2.15.0+
Additional Details
Additional context
#7286 (which bumps Jackson to 2.15.0) has been merged to future releases
Questions
Is OpenSearch 1.3.x affected by this VULN (https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538)?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
LibrariesLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respoLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respobugSomething isn't workingSomething isn't working