Repository navigation
fix: address Jackson 1 and Netty vulnerabilities #19808
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
0a388ac
6418030
ee5d98c
25e4abb
cbea7e6
79bf16a
74081f9
432cb7e
31fedb7
3ae5b49
cdf3841
e611ee3
b5ccdb0
a16bea0
ed5d46e
3b80ce5
6c598c2
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -60,6 +60,11 @@ | |
| <groupId>org.codehaus.jackson</groupId> | ||
| <artifactId>jackson-mapper-asl</artifactId> | ||
| </exclusion> | ||
| <exclusion> | ||
| <!-- ambari-metrics-common shades Jackson 1.9.13 and uses the relocated copy at runtime --> | ||
| <groupId>org.codehaus.jackson</groupId> | ||
| <artifactId>jackson-xc</artifactId> | ||
| </exclusion> | ||
| <exclusion> | ||
| <!-- ambari depends on hadoop-annotations, which in turn depends on | ||
| ${java.home}/../lib/tools.jar, which was removed in Java 9+ --> | ||
|
|
@@ -119,16 +124,6 @@ | |
| <artifactId>JUnitParams</artifactId> | ||
|
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [P2] Ambari still ships Jackson 1 via jackson-xc The deletion removes only test-scoped jackson-core-asl and jackson-mapper-asl. The compile-scoped ambari-metrics-common dependency remains, and dependency-tree validation reports that it still resolves org.codehaus.jackson:jackson-xc. The production extension therefore continues to ship EOL Jackson 1 code. Upgrade or replace Ambari, or remove the remaining artifact with a verified runtime-compatible alternative.
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This is addressed in the same commit, 3b80ce5. The compile-scoped ambari-metrics-common dependency now explicitly excludes org.codehaus.jackson:jackson-xc, so dependency-tree validation no longer resolves any unrelocated org.codehaus.jackson artifact. The Ambari jar necessarily retains its relocated Jackson 1.9.13 implementation because AbstractTimelineMetricsSink uses it and 2.7.0.0.0 is the latest published release; I documented and retained the explicit CVE suppression assessment for that shaded copy. All 28 Ambari emitter tests pass with the exclusion. |
||
| <scope>test</scope> | ||
| </dependency> | ||
| <dependency> | ||
| <groupId>org.codehaus.jackson</groupId> | ||
| <artifactId>jackson-core-asl</artifactId> | ||
| <scope>test</scope> | ||
| </dependency> | ||
| <dependency> | ||
| <groupId>org.codehaus.jackson</groupId> | ||
| <artifactId>jackson-mapper-asl</artifactId> | ||
| <scope>test</scope> | ||
| </dependency> | ||
| </dependencies> | ||
|
|
||
| <build> | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[P2] Jackson 1 remains bundled
Removing the test dependencies hides the Maven alert, but ambari-metrics-common:2.7.0.0.0 still embeds Jackson 1.9.13 under a relocated package and uses it to serialize metrics in production. The bundled Ambari extension therefore still ships Jackson 1; upgrade or replace that dependency, or explicitly assess and retain the suppression.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Addressed in commit 3b80ce5. ambari-metrics-common:2.7.0.0.0 is the latest published release, and its AbstractTimelineMetricsSink uses the relocated Jackson 1.9.13 classes bundled inside that jar, so upgrading it is not a compatible drop-in fix. I added an explicit exclusion for org.codehaus.jackson:jackson-xc, removing the unrelocated Jackson artifact from the emitter dependency graph, and documented the retained explicit CVE assessment for the unavoidable shaded runtime copy. The focused dependency tree now has no org.codehaus.jackson entries, and all 28 Ambari emitter tests pass.