apache / apache/pinot

org.codehaus.jackson:jackson-mapper-asl is not maintained and has a serious CVE

Open
#8,144 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
6.1k
Forks
1.5k
Avg merge
1d 21h
Merged PRs (30d)
189

Description

[org.codehaus.jackson:jackson-mapper-asl](https://github.com/advisories/GHSA-r6j9-8759-g62w)

it should be easy to switch to jackson 2.x - very similar api

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declarations and usages of org.codehaus.jackson:jackson-mapper-asl, then review the Jackson 2.x compatibility needs described in the issue. Check the affected build and tests after the dependency migration; done means the vulnerable dependency is removed and the project still passes its relevant tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.