Skip to content

Commit be15fbc

Browse files
[CVE-2020-36518] Update jackson-databind to 2.13.2.2 (#2599) (#2647)
Signed-off-by: Andriy Redko <andriy.redko@aiven.io> (cherry picked from commit d8a1ba6) Co-authored-by: Andriy Redko <andriy.redko@aiven.io>
1 parent 39dda1d commit be15fbc

24 files changed

+18
-17
lines changed

buildSrc/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -116,7 +116,7 @@ dependencies {
116116
api 'com.avast.gradle:gradle-docker-compose-plugin:0.14.12'
117117
api 'org.apache.maven:maven-model:3.6.2'
118118
api 'com.networknt:json-schema-validator:1.0.68'
119-
api "com.fasterxml.jackson.core:jackson-databind:${props.getProperty('jackson')}"
119+
api "com.fasterxml.jackson.core:jackson-databind:${props.getProperty('jackson_databind')}"
120120

121121
testFixturesApi "junit:junit:${props.getProperty('junit')}"
122122
testFixturesApi "com.carrotsearch.randomizedtesting:randomizedtesting-runner:${props.getProperty('randomizedrunner')}"

buildSrc/version.properties

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ bundled_jdk = 17.0.2+8
1010
spatial4j = 0.7
1111
jts = 1.15.0
1212
jackson = 2.13.2
13+
jackson_databind = 2.13.2.2
1314
snakeyaml = 1.26
1415
icu4j = 70.1
1516
supercsv = 2.4.0

distribution/tools/upgrade-cli/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ dependencies {
1515
compileOnly project(":server")
1616
compileOnly project(":libs:opensearch-cli")
1717
implementation "com.fasterxml.jackson.core:jackson-core:${versions.jackson}"
18-
implementation "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
18+
implementation "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
1919
implementation "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
2020
testImplementation project(":test:framework")
2121
testImplementation 'com.google.jimfs:jimfs:1.2'
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ffeb635597d093509f33e1e94274d14be610f933

distribution/tools/upgrade-cli/licenses/jackson-databind-2.13.2.jar.sha1

Lines changed: 0 additions & 1 deletion
This file was deleted.

libs/dissect/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ dependencies {
3434
}
3535
testImplementation "com.fasterxml.jackson.core:jackson-core:${versions.jackson}"
3636
testImplementation "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
37-
testImplementation "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
37+
testImplementation "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
3838
}
3939

4040
tasks.named('forbiddenApisMain').configure {

modules/ingest-geoip/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ dependencies {
4242
api('com.maxmind.geoip2:geoip2:2.16.1')
4343
// geoip2 dependencies:
4444
api("com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}")
45-
api("com.fasterxml.jackson.core:jackson-databind:${versions.jackson}")
45+
api("com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}")
4646
api('com.maxmind.db:maxmind-db:2.0.0')
4747

4848
testImplementation 'org.elasticsearch:geolite2-databases:20191119'
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ffeb635597d093509f33e1e94274d14be610f933

modules/ingest-geoip/licenses/jackson-databind-2.13.2.jar.sha1

Lines changed: 0 additions & 1 deletion
This file was deleted.

plugins/discovery-ec2/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ dependencies {
5050
api "commons-logging:commons-logging:${versions.commonslogging}"
5151
api "org.apache.logging.log4j:log4j-1.2-api:${versions.log4j}"
5252
api "commons-codec:commons-codec:${versions.commonscodec}"
53-
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
53+
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
5454
api "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
5555
}
5656

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ffeb635597d093509f33e1e94274d14be610f933

plugins/discovery-ec2/licenses/jackson-databind-2.13.2.jar.sha1

Lines changed: 0 additions & 1 deletion
This file was deleted.

plugins/repository-azure/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ dependencies {
6262
api 'io.projectreactor.netty:reactor-netty-http:1.0.16'
6363
api "org.slf4j:slf4j-api:${versions.slf4j}"
6464
api "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
65-
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
65+
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
6666
api "com.fasterxml.jackson.datatype:jackson-datatype-jsr310:${versions.jackson}"
6767
api "com.fasterxml.jackson.dataformat:jackson-dataformat-xml:${versions.jackson}"
6868
api "com.fasterxml.jackson.module:jackson-module-jaxb-annotations:${versions.jackson}"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ffeb635597d093509f33e1e94274d14be610f933

plugins/repository-azure/licenses/jackson-databind-2.13.2.jar.sha1

Lines changed: 0 additions & 1 deletion
This file was deleted.

plugins/repository-hdfs/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ dependencies {
6464
api 'org.apache.htrace:htrace-core4:4.2.0-incubating'
6565
api "org.apache.logging.log4j:log4j-core:${versions.log4j}"
6666
api 'org.apache.avro:avro:1.10.2'
67-
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
67+
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
6868
api 'com.google.code.gson:gson:2.9.0'
6969
runtimeOnly 'com.google.guava:guava:30.1.1-jre'
7070
api 'com.google.protobuf:protobuf-java:3.19.3'
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ffeb635597d093509f33e1e94274d14be610f933

plugins/repository-hdfs/licenses/jackson-databind-2.13.2.jar.sha1

Lines changed: 0 additions & 1 deletion
This file was deleted.

plugins/repository-s3/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ dependencies {
5858
api "org.apache.logging.log4j:log4j-1.2-api:${versions.log4j}"
5959
api "commons-codec:commons-codec:${versions.commonscodec}"
6060
api "com.fasterxml.jackson.core:jackson-core:${versions.jackson}"
61-
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
61+
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
6262
api "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
6363
api "com.fasterxml.jackson.dataformat:jackson-dataformat-cbor:${versions.jackson}"
6464
api "joda-time:joda-time:${versions.joda}"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ffeb635597d093509f33e1e94274d14be610f933

plugins/repository-s3/licenses/jackson-databind-2.13.2.jar.sha1

Lines changed: 0 additions & 1 deletion
This file was deleted.

qa/os/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ dependencies {
5050

5151
testImplementation "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
5252
testImplementation "com.fasterxml.jackson.core:jackson-core:${versions.jackson}"
53-
testImplementation "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
53+
testImplementation "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
5454
}
5555

5656
tasks.named('forbiddenApisTest').configure {

qa/wildfly/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ dependencies {
5050
}
5151
api "com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}"
5252
api "com.fasterxml.jackson.core:jackson-core:${versions.jackson}"
53-
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
53+
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
5454
api "com.fasterxml.jackson.jaxrs:jackson-jaxrs-json-provider:${versions.jackson}"
5555
api "com.fasterxml.jackson.jaxrs:jackson-jaxrs-base:${versions.jackson}"
5656
api "com.fasterxml.jackson.module:jackson-module-jaxb-annotations:${versions.jackson}"

test/fixtures/hdfs-fixture/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,6 @@ dependencies {
4141
api 'com.google.code.gson:gson:2.9.0'
4242
api "org.bouncycastle:bcpkix-jdk15on:${versions.bouncycastle}"
4343
api "com.fasterxml.jackson.jaxrs:jackson-jaxrs-json-provider:${versions.jackson}"
44-
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson}"
44+
api "com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}"
4545
api 'net.minidev:json-smart:2.4.8'
4646
}

0 commit comments

Comments
 (0)