Critical and High Vulnerabilities in these DataHub components (v0.9.6.2)
-> datahub-ingestion
->datahub-upgrade
->datahub-frontend
->datahub-kafka-setup
Details
Upstream dependencies for jackson-databind v2.4.0 and v2.10.0
CVE-2022-42004
CVE-2020-10673
CVE-2020-36186
CVE-2019-12086
CVE-2018-12022
Resolution
For datahub-ingestion
production of a -slim
without pyspark.
Remaining jackson components are upgraded to v2.15.2rc2 as of DataHub v0.10.2
Critical and High Vulnerabilities in these DataHub components (v0.9.6.2)
-> datahub-ingestion
->datahub-upgrade
->datahub-frontend
->datahub-kafka-setup
Details
Upstream dependencies for jackson-databind v2.4.0 and v2.10.0
CVE-2022-42004
CVE-2020-10673
CVE-2020-36186
CVE-2019-12086
CVE-2018-12022
Resolution
For
datahub-ingestion
production of a-slim
without pyspark.Remaining jackson components are upgraded to v2.15.2rc2 as of DataHub v0.10.2