[ https://issues.apache.org/jira/browse/HIVE-23338?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17101659#comment-17101659 ]
Peter Vary edited comment on HIVE-23338 at 5/7/20, 1:40 PM: ------------------------------------------------------------ Shall we change the version in main pom.xml? was (Author: pvary): +1 > Bump jackson-databind version up to 2.9.10.4 > -------------------------------------------- > > Key: HIVE-23338 > URL: https://issues.apache.org/jira/browse/HIVE-23338 > Project: Hive > Issue Type: Improvement > Reporter: Karen Coppage > Assignee: Karen Coppage > Priority: Major > Attachments: HIVE-23338.01.patch, HIVE-23338.01.patch, > HIVE-23338.01.patch, HIVE-23338.01.patch, HIVE-23338.02.patch > > > com.fasterxml.jackson.core:jackson-databind:2.9.9 is exploitable. > And exclude a transitive dependency on > com.fasterxml.jackson.core:jackson-databind:2.6.5, which is also exploitable. -- This message was sent by Atlassian Jira (v8.3.4#803005)