Package
hadoop-fips-3.3.6
Component
jackson-databind
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This jackson copy is present in the bundled Maven repository only because frontend-maven-plugin 1.11.2 (via frontend-plugin-core 1.11.2, which declares jackson-databind 2.9.10.5 and jackson-core 2.9.10) resolves it while building the YARN catalog webapp. It is not used by any Hadoop artifact: hadoop-project's dependencyManagement pins jackson-core and jackson-databind (jackson2.version / jackson2.databind.version) for all Hadoop modules. This copy is only loaded inside a Maven build-plugin classloader, where its input is the consuming project's own build configuration, not attacker-controlled data.
Status
Justification
Impact
This jackson copy is present in the bundled Maven repository only because frontend-maven-plugin 1.11.2 (via frontend-plugin-core 1.11.2, which declares jackson-databind 2.9.10.5 and jackson-core 2.9.10) resolves it while building the YARN catalog webapp. It is not used by any Hadoop artifact: hadoop-project's dependencyManagement pins jackson-core and jackson-databind (jackson2.version / jackson2.databind.version) for all Hadoop modules. This copy is only loaded inside a Maven build-plugin classloader, where its input is the consuming project's own build configuration, not attacker-controlled data.
Status