Package
druid
Component
jackson-core
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The Druid HDFS storage extension includes the Apache Hadoop hadoop-client-runtime 3.5.0 jar, which bundles its own shaded copy of Jackson 2.18.6. That shaded copy cannot be upgraded separately from the jar, and 3.5.0 is the latest Hadoop release, so no fixed hadoop-client-runtime is available yet. This will be remediated when Hadoop publishes a release that bundles a patched Jackson version.
Status