mirror of https://github.com/apache/druid.git
550a66d71e
The current version of jackson-databind is flagged for vulnerabilities CVE-2020-28491 (Although cbor format is not used in druid), CVE-2020-36518 (Seems genuine as deeply nested json in can cause resource exhaustion). Updating the dependency to the latest version 2.12.7 to fix these vulnerabilities. |
||
---|---|---|
.. | ||
main | ||
test/java/org/apache/druid/emitter/kafka |