[ https://issues.apache.org/jira/browse/FLINK-37682?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17945834#comment-17945834 ]
Ferenc Csaky commented on FLINK-37682: -------------------------------------- I'm not necessarily against bumping Jackson, but this CVE is not convincing at all. There is quite a good read about it here: https://github.com/FasterXML/jackson-databind/issues/3972 > Upgrade Jackson Lib to Address CVE-2023-35116 > ---------------------------------------------- > > Key: FLINK-37682 > URL: https://issues.apache.org/jira/browse/FLINK-37682 > Project: Flink > Issue Type: Improvement > Components: Kubernetes Operator > Reporter: Atul Sharma > Priority: Major > Labels: pull-request-available > > Flink Kuberenetes Operator uses jackson with 2.15.0 and has CVE-2023-35116: > CVE-2023-35116: jackson-databind package versions before 2.15.2 are > vulnerable to Denial of Service (DoS) > https://nvd.nist.gov/vuln/detail/cve-2023-35116 -- This message was sent by Atlassian Jira (v8.20.10#820010)