← All tasks
javadeeplearning4j/deeplearning4j #9138Not a task: not reproduced

jackson-databind vulnerability

envgap__deeplearning4j__deeplearning4j-9138

01 / FAILURE SIGNATURE

As reported upstream

`[ERROR] jackson-1.0.0-beta7.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.xml: CVE-2020-25649`
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
652b8540836b28f3ad4d4eae980be8517d922e8e
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

deeplearning4j/deeplearning4j #9138 · read the original issue
On our CI system, a CVE scan detected a vulnerability due to the shaded com.fasterxml.jackson.core version pulled in by jackson-1.0.0-beta7.



`[ERROR] jackson-1.0.0-beta7.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.xml: CVE-2020-25649`



The issue seems to have been fixed in jackson-databind already as of milestone 2.9.10.7 (see https://github.com/FasterXML/jackson-databind/issues/2589).



Version Information

Deeplearning4j version: 1.0.0-beta7

Platform information: Linux/Mac OS



Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]