[ https://issues.apache.org/jira/browse/FLINK-37078?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Robert Metzger resolved FLINK-37078. ------------------------------------ Fix Version/s: 2.1.0 Resolution: Fixed Merged to master for 2.1 in https://github.com/apache/flink/commit/412fc8c124f3ae4da64d28b4042680b25857bde1. > Update jackson-mapper-asl dependency > ------------------------------------ > > Key: FLINK-37078 > URL: https://issues.apache.org/jira/browse/FLINK-37078 > Project: Flink > Issue Type: Bug > Components: FileSystems > Reporter: Anupam Aggarwal > Assignee: Anupam Aggarwal > Priority: Minor > Labels: pull-request-available > Fix For: 2.1.0 > > > Flink includes org.codehaus.jackson:jackson-mapper-asl:1.9.13 which contains > [CVE-2019-10202|https://nvd.nist.gov/vuln/detail/cve-2019-10202] > There seems to be a version - > org.codehaus.jackson/jackson-mapper-asl/1.9.14.jdk17-redhat-00001 (in redhat > GA repository) which is not flagged as vulnerable > More details at [https://nvd.nist.gov/vuln/detail/cve-2019-10202] -- This message was sent by Atlassian Jira (v8.20.10#820010)