jackson-databind vulnerability
envgap__deeplearning4j__deeplearning4j-9138
01 / FAILURE SIGNATURE
As reported upstream
`[ERROR] jackson-1.0.0-beta7.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.xml: CVE-2020-25649`
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
652b8540836b28f3ad4d4eae980be8517d922e8e- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
deeplearning4j/deeplearning4j #9138 · read the original issue
On our CI system, a CVE scan detected a vulnerability due to the shaded com.fasterxml.jackson.core version pulled in by jackson-1.0.0-beta7. `[ERROR] jackson-1.0.0-beta7.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.xml: CVE-2020-25649` The issue seems to have been fixed in jackson-databind already as of milestone 2.9.10.7 (see https://github.com/FasterXML/jackson-databind/issues/2589). Version Information Deeplearning4j version: 1.0.0-beta7 Platform information: Linux/Mac OS
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]