Skip to content

fix: address Jackson 1 and Netty vulnerabilities - #19808

Closed
FrankChen021 wants to merge 17 commits into
apache:masterfrom
FrankChen021:codex/deps-remove-jackson1
Closed

FrankChen021 wants to merge 17 commits into
apache:masterfrom
FrankChen021:codex/deps-remove-jackson1

Conversation

@FrankChen021

@FrankChen021 FrankChen021 commented Jul 30, 2026 •

Copy link
Copy Markdown
Member

Related

Supersedes #18456.

Summary

  • remove the unused Jackson 1 version property and dependency-management entries
  • remove the explicit test-scope jackson-core-asl and jackson-mapper-asl dependencies from ambari-metrics-emitter
  • remove the now-obsolete OWASP suppression for jackson-mapper-asl
  • retain the Ambari transitive exclusions that prevent Jackson 1 core/mapper from entering the production dependency graph
  • explicitly suppress Netty 4 module advisories misattributed to the EOL Netty 3 artifact, while keeping future advisories visible

Root cause

Dependabot alerts #2 and #221 report org.codehaus.jackson:jackson-mapper-asl:1.9.13. Jackson 1 is end-of-life and has no patched release. The Ambari Metrics dependency already excluded Jackson 1 core and mapper from production, but the module explicitly added both artifacts back in test scope. The root POM also kept global dependency-management entries for them.

Druid's Ambari emitter source and tests use Jackson 2 (com.fasterxml.jackson), so the explicit Jackson 1 test dependencies are unnecessary.

Why the Netty changes are included

Removing the obsolete Jackson suppression changes owasp-dependency-check-suppressions.xml, which is the path trigger for Druid's full OWASP dependency-check workflow. That repository-wide scan exposed pre-existing findings against netty-3.10.6.Final. GitHub's advisory records scope each reported CVE to Netty 4 module artifacts such as netty-codec-http, netty-resolver-dns, and netty-handler, but Dependency-Check's generic Netty CPE mapping also attaches them to the monolithic Netty 3 artifact.

The misattributed CVEs are listed explicitly rather than using a package-wide wildcard. This allows the security workflow to assess the Jackson removal without failing on Netty 4-only findings, while ensuring that future Netty advisories remain visible and trigger a fresh assessment. Migrating Druid's legacy NettyHttpClient from Netty 3 to Netty 4 remains a separate change.

Impact

The Ambari emitter no longer resolves jackson-core-asl or jackson-mapper-asl, allowing Dependabot alerts #2 and #221 to close without hiding an active vulnerable dependency. Runtime behavior is unchanged because those artifacts were already excluded from the production Ambari dependency path.

Netty 3 remains unchanged at runtime. The OWASP suppression only covers explicitly assessed Netty 4 module advisories that Dependency-Check misattributes to Netty 3; newly published CVEs remain visible.

Validation

  • mvn -ntp dependency:tree -pl extensions-contrib/ambari-metrics-emitter -Dincludes=org.codehaus.jackson -Dverbose -Pskip-static-checks -Dweb.console.skip=true -T1C
    • confirms neither jackson-core-asl nor jackson-mapper-asl is resolved; Ambari's separate jackson-xc artifact remains
  • mvn -ntp test -pl extensions-contrib/ambari-metrics-emitter -Pskip-static-checks -Dweb.console.skip=true -T1C
    • 28 tests passed
  • checked every Netty finding from the failed security job against the GitHub Advisory Database
    • each advisory targets Netty 4 module coordinates rather than the monolithic io.netty:netty Netty 3 artifact
  • validated owasp-dependency-check-suppressions.xml against Dependency-Check's dependency-suppression.1.3.xsd
  • git diff --check

The focused local OWASP run could not execute without a populated NVD database; the GitHub security workflow provides the authoritative rescan with its configured NVD access.

Caveats

This intentionally does not upgrade Ambari or alter its binary API. The existing exclusions remain in place to prevent its transitive Jackson 1 core/mapper dependencies from returning.

The explicit Netty 3 suppressions are not a claim that Netty 3 is patched. They cover only individually assessed Netty 4-only advisories misattributed through the generic CPE; actual Netty 3 remediation still requires the separate NettyHttpClient migration.

Created by GPT-5.6-Sol.

@FrankChen021
FrankChen021 marked this pull request as ready for review July 30, 2026 14:47
Copilot AI review requested due to automatic review settings July 30, 2026 14:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Removes end-of-life Jackson 1 (org.codehaus.jackson) dependencies and related OWASP suppression to close Dependabot alerts while preserving existing transitive exclusions that keep Jackson 1 out of the production dependency graph.

Changes:

  • Removed the unused Jackson 1 version property and dependency-management entries from the root POM.
  • Removed explicit test-scope jackson-core-asl / jackson-mapper-asl dependencies from extensions-contrib/ambari-metrics-emitter.
  • Removed the now-obsolete OWASP Dependency-Check suppression for jackson-mapper-asl:1.9.13.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
pom.xml Removes Jackson 1 version property and dependency-management entries to prevent resolution of vulnerable artifacts.
owasp-dependency-check-suppressions.xml Drops suppression that was only needed due to test-scope Jackson 1 usage.
extensions-contrib/ambari-metrics-emitter/pom.xml Removes explicit test dependencies on Jackson 1 core/mapper artifacts.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@FrankChen021 FrankChen021 changed the title Remove vulnerable Jackson 1 dependencies fix: remove vulnerable Jackson 1 dependencies Jul 30, 2026
@FrankChen021

Copy link
Copy Markdown
Member Author

The failing KafkaIndexFaultToleranceTest.test_supervisorRecords_afterHistoricalRestart appears to be an unrelated flaky-test failure caused by publishing immediately after topic creation, before all partition leaders are ready. PR #19824 adds the topic-leader readiness wait and includes focused regression coverage for this scenario.

@FrankChen021 FrankChen021 changed the title fix: remove vulnerable Jackson 1 dependencies fix: address Jackson 1 and Netty vulnerabilities Jul 30, 2026

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity Findings
P0 0
P1 1
P2 0
P3 0
Total 1

Reviewed 4 of 4 changed files.


This is an automated review by Codex GPT-5.6-Sol

Comment thread owasp-dependency-check-suppressions.xml Outdated

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity Findings
P0 0
P1 0
P2 1
P3 0
Total 1

Reviewed 4 of 4 changed files. The Jackson 1 compatibility concern is resolved, but the new catch-all Netty 3 suppression hides future advisories from OWASP CI.


This is an automated review by Codex GPT-5.6-Sol

Comment thread owasp-dependency-check-suppressions.xml Outdated

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have reviewed the code for correctness, edge cases, concurrency, and integration risks; no issues found.

Reviewed 4 of 4 changed files. The prior catch-all Netty 3 suppression concern is resolved: the wildcard has been replaced with an explicit CVE list, so future advisories remain visible.


This is an automated review by Codex GPT-5.6-Sol

@FrankChen021
FrankChen021 requested a lite review from Copilot August 5, 2026 12:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

Suppressed comments (1)

owasp-dependency-check-suppressions.xml:347

  • This suppression is scoped only by packageUrl (uuid@7.0.3), which makes it repository-wide for that dependency version. If uuid@7.0.3 is used outside the web-console (now or in the future), this would also hide a potentially real finding there. Prefer scoping the suppression to the specific lockfile/build artifact for the web-console (e.g., add a filePath/related matcher supported by Dependency-Check suppressions) so the justification in the notes matches the suppression’s actual impact.
  <suppress>
    <notes><![CDATA[
    web-console uses uuid v4() only to generate query IDs. GHSA-w5hq-g745-h8pq
    (CVE-2026-41907) affects the v3/v5/v6 buffer APIs; v4 is not affected.
    Revisit this suppression when uuid is upgraded.
    ]]></notes>
    <packageUrl regex="true">^pkg:npm/uuid@7\.0\.3$</packageUrl>
    <vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
    <cve>CVE-2026-41907</cve>
  </suppress>

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have reviewed the updated head for correctness, dependency compatibility, security, and integration risks; no issues found.

Reviewed 3 of 3 changed files. The prior Netty catch-all suppression concern remains resolved because the suppression is still limited to explicit CVEs.


This is an automated review by Codex GPT-5.6-Sol

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity Findings
P0 0
P1 0
P2 1
P3 0
Total 1
Severity Findings
P0 0
P1 0
P2 1
P3 0
Total 1

Reviewed 3 of 3 changed files. The prior catch-all Netty suppression concern remains resolved, but the production Ambari extension still bundles Jackson 1.


This is an automated review by Codex GPT-5.6-Luna(max)

@@ -119,16 +119,6 @@
<artifactId>JUnitParams</artifactId>

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Jackson 1 remains bundled

Removing the test dependencies hides the Maven alert, but ambari-metrics-common:2.7.0.0.0 still embeds Jackson 1.9.13 under a relocated package and uses it to serialize metrics in production. The bundled Ambari extension therefore still ships Jackson 1; upgrade or replace that dependency, or explicitly assess and retain the suppression.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in commit 3b80ce5. ambari-metrics-common:2.7.0.0.0 is the latest published release, and its AbstractTimelineMetricsSink uses the relocated Jackson 1.9.13 classes bundled inside that jar, so upgrading it is not a compatible drop-in fix. I added an explicit exclusion for org.codehaus.jackson:jackson-xc, removing the unrelocated Jackson artifact from the emitter dependency graph, and documented the retained explicit CVE assessment for the unavoidable shaded runtime copy. The focused dependency tree now has no org.codehaus.jackson entries, and all 28 Ambari emitter tests pass.

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity Findings
P0 0
P1 0
P2 1
P3 0
Total 1

Reviewed 3 of 3 changed files.

The existing Ambari Jackson 1 finding remains unresolved; the prior Netty catch-all suppression concern is resolved.

Validation: git diff --check and XML parsing passed; the packet reports 28 focused tests passed.


This is an automated review by Codex GPT-5.6-Luna(max)

@@ -119,16 +119,6 @@
<artifactId>JUnitParams</artifactId>

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Ambari still ships Jackson 1 via jackson-xc

The deletion removes only test-scoped jackson-core-asl and jackson-mapper-asl. The compile-scoped ambari-metrics-common dependency remains, and dependency-tree validation reports that it still resolves org.codehaus.jackson:jackson-xc. The production extension therefore continues to ship EOL Jackson 1 code. Upgrade or replace Ambari, or remove the remaining artifact with a verified runtime-compatible alternative.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is addressed in the same commit, 3b80ce5. The compile-scoped ambari-metrics-common dependency now explicitly excludes org.codehaus.jackson:jackson-xc, so dependency-tree validation no longer resolves any unrelocated org.codehaus.jackson artifact. The Ambari jar necessarily retains its relocated Jackson 1.9.13 implementation because AbstractTimelineMetricsSink uses it and 2.7.0.0.0 is the latest published release; I documented and retained the explicit CVE suppression assessment for that shaded copy. All 28 Ambari emitter tests pass with the exclusion.

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have reviewed the code for correctness, edge cases, concurrency, and integration risks; no issues found.

Reviewed 3 of 3 changed files.

Validation: git diff --check and XML parsing passed; no builds or tests were run.


This is an automated review by Codex GPT-5.6-Luna(max)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants