parseq icon indicating copy to clipboard operation
parseq copied to clipboard

Bump vulnerable dependency on jackson-mapper-asl (CVE-2019-10172)

Open jjoyce0510 opened this issue 2 years ago • 5 comments

Parseq depends on jackson-mapper-asl, which has not been updated for many years and has been since deprecated, moved to jackson-databind under FastXML.

This library has a serious CVE that can only be addressed by migrating from jackson-mapper-asl to jackson-databind module at a later version (preferably 2.13.2.2)

This ticket is for doing this migration with Parseq. Because Restli client depends on Parseq, this dependency bubbles up to anyone depending on Rest.li client as well.

jjoyce0510 avatar May 05 '22 05:05 jjoyce0510

@junchuanwang do you think we can get this one prioritized?

jjoyce0510 avatar May 05 '22 19:05 jjoyce0510

@jjoyce0510 do you think you can raise a PR? I will review it. My hunch is chaging the import path name ( org.codehaus.jackson vs com.fasterxml.jackson.core) is the only thing needed.

junchuanwang avatar May 05 '22 20:05 junchuanwang

@jjoyce0510 @junchuanwang IS this change released or do we have any ETA for this fix? We are planning to use Parseq post this fix.

fm-gawdeprasad avatar Sep 06 '22 08:09 fm-gawdeprasad

@jjoyce0510 @junchuanwang : I have made the required changes but don't have permission to push these changes or create a PR. I have attached a file containing the changes.

Can one of you please review and push these changes out ASAP? jackson-update.txt

nipundave avatar Oct 18 '22 09:10 nipundave

@jjoyce0510 @junchuanwang : I have made the required changes but don't have permission to push these changes or create a PR. I have attached a file containing the changes.

Can one of you please review and push these changes out ASAP? jackson-update.txt

@evanw555 I think this is a safe change, can you convert this to an PR?

junchuanwang avatar Oct 25 '22 19:10 junchuanwang