Upgrade jackson Due to CVE-2022-42003 (#21176)

Signed-off-by: Astralidea <astralidea@163.com>
This commit is contained in:
Felix Li 2023-04-07 22:00:32 +08:00 committed by GitHub
parent ff1fa25a18
commit 8175f50d93
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
4 changed files with 4 additions and 4 deletions

View File

@ -250,7 +250,7 @@ under the License.
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson.version}.1</version>
<version>${jackson.version}.2</version>
</dependency>
<!-- https://mvnrepository.com/artifact/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml -->

View File

@ -43,7 +43,7 @@ under the License.
<thrift.version>0.14.1</thrift.version>
<tomcat.version>8.5.70</tomcat.version>
<log4j.version>2.17.1</log4j.version>
<jackson.version>2.13.4.1</jackson.version>
<jackson.version>2.13.4.2</jackson.version>
</properties>
<profiles>

View File

@ -20,7 +20,7 @@
<presto.hive.version>3.0.0-8</presto.hive.version>
<hudi.version>0.12.2</hudi.version>
<fasterxml.version>2.13.4</fasterxml.version>
<fasterxml.jackson.databind.version>2.13.4.1</fasterxml.jackson.databind.version>
<fasterxml.jackson.databind.version>2.13.4.2</fasterxml.jackson.databind.version>
<esotericsoftware.kryo.shaded.version>4.0.2</esotericsoftware.kryo.shaded.version>
<luben.zstd.jni.version>1.5.4-2</luben.zstd.jni.version>
</properties>

View File

@ -22,7 +22,7 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.13.4.1</version>
<version>2.13.4.2</version>
</dependency>
</dependencies>