Skip to content

(avro) Snyk Reports a Critical Vulnerability (org.codehaus.jackson:jackson-mapper-asl Improper Input Validation) -- NOT APPLICABLE (polymorphic deserialization) #412

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
tomthehumanmettle opened this issue Oct 30, 2023 · 3 comments
Labels

Comments

@tomthehumanmettle
Copy link

Introduced through: com.fasterxml.jackson.dataformat:[email protected] › org.apache.avro:[email protected] › org.codehaus.jackson:[email protected]

Link to issue: https://app.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSJACKSON-3326362

@cowtowncoder
Copy link
Member

Nothing we can do without figuring out how to upgrade to Avro 1.9.0 or later, see #167 f.ex.

This itself is dup of #187 so will close.

@tomthehumanmettle
Copy link
Author

I don't think this should be closed, as the earlier issue does not mention the fact that a critically vulnerable transitive dependency is pulled in @cowtowncoder. I think this should remain open to provide visibility of this, as it's an issue that is going to prevent many organisations from using this lib due to security policies.

@cowtowncoder
Copy link
Member

I disagree. The root problem is that we cannot update to a later version. Anyone looking for specific vuln can find this one, even if closed.

Also: vulnerability is also non-applicable, as usual (vast majority of vulns/cves are non-applicable based on my experience) -- it only affects Polymorphic Deserialization, none of which is used by Avro format module or apache avro library.

@cowtowncoder cowtowncoder changed the title Snyk Reports a Critical Vulnerability (org.codehaus.jackson:jackson-mapper-asl Improper Input Validation) (avro) Snyk Reports a Critical Vulnerability (org.codehaus.jackson:jackson-mapper-asl Improper Input Validation) -- NOT APPLICABLE (polymorphic deserialization) Oct 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants