Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 5 additions & 10 deletions extensions-contrib/ambari-metrics-emitter/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,11 @@
<groupId>org.codehaus.jackson</groupId>
<artifactId>jackson-mapper-asl</artifactId>
</exclusion>
<exclusion>
<!-- ambari-metrics-common shades Jackson 1.9.13 and uses the relocated copy at runtime -->
<groupId>org.codehaus.jackson</groupId>
<artifactId>jackson-xc</artifactId>
</exclusion>
<exclusion>
<!-- ambari depends on hadoop-annotations, which in turn depends on
${java.home}/../lib/tools.jar, which was removed in Java 9+ -->
Expand Down Expand Up @@ -119,16 +124,6 @@
<artifactId>JUnitParams</artifactId>

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Jackson 1 remains bundled

Removing the test dependencies hides the Maven alert, but ambari-metrics-common:2.7.0.0.0 still embeds Jackson 1.9.13 under a relocated package and uses it to serialize metrics in production. The bundled Ambari extension therefore still ships Jackson 1; upgrade or replace that dependency, or explicitly assess and retain the suppression.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in commit 3b80ce5. ambari-metrics-common:2.7.0.0.0 is the latest published release, and its AbstractTimelineMetricsSink uses the relocated Jackson 1.9.13 classes bundled inside that jar, so upgrading it is not a compatible drop-in fix. I added an explicit exclusion for org.codehaus.jackson:jackson-xc, removing the unrelocated Jackson artifact from the emitter dependency graph, and documented the retained explicit CVE assessment for the unavoidable shaded runtime copy. The focused dependency tree now has no org.codehaus.jackson entries, and all 28 Ambari emitter tests pass.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Ambari still ships Jackson 1 via jackson-xc

The deletion removes only test-scoped jackson-core-asl and jackson-mapper-asl. The compile-scoped ambari-metrics-common dependency remains, and dependency-tree validation reports that it still resolves org.codehaus.jackson:jackson-xc. The production extension therefore continues to ship EOL Jackson 1 code. Upgrade or replace Ambari, or remove the remaining artifact with a verified runtime-compatible alternative.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is addressed in the same commit, 3b80ce5. The compile-scoped ambari-metrics-common dependency now explicitly excludes org.codehaus.jackson:jackson-xc, so dependency-tree validation no longer resolves any unrelocated org.codehaus.jackson artifact. The Ambari jar necessarily retains its relocated Jackson 1.9.13 implementation because AbstractTimelineMetricsSink uses it and 2.7.0.0.0 is the latest published release; I documented and retained the explicit CVE suppression assessment for that shaded copy. All 28 Ambari emitter tests pass with the exclusion.

<scope>test</scope>
</dependency>
<dependency>
<groupId>org.codehaus.jackson</groupId>
<artifactId>jackson-core-asl</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.codehaus.jackson</groupId>
<artifactId>jackson-mapper-asl</artifactId>
<scope>test</scope>
</dependency>
</dependencies>

<build>
Expand Down
82 changes: 71 additions & 11 deletions owasp-dependency-check-suppressions.xml
Original file line number Diff line number Diff line change
Expand Up @@ -241,19 +241,11 @@
<cve>CVE-2023-0833</cve> <!-- Suppressed since okhttp requests in Druid are internal, and not user-facing -->
</suppress>

<suppress>
<!-- TODO: Fix by updating ambari-metrics-emitter's transitive hadoop dependency -->
<notes><![CDATA[
file name: jackson-mapper-asl-1.9.13.jar
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.codehaus\.jackson/jackson\-mapper\-asl@1.9.13$</packageUrl>
<cvssBelow>10</cvssBelow> <!-- suppress all CVEs for jackson-mapper-asl:1.9.13; pulled in (test scope only) via ambari-metrics-emitter -->
</suppress>

<suppress>
<!-- TODO: Fix by updating org.apache.druid.java.util.http.client.NettyHttpClient to use netty 4 -->
<notes><![CDATA[
file name: netty-3.10.6.Final.jar
The CVEs in this rule are suppressed only for io.netty:netty:3.10.6.Final.
]]></notes>
<packageUrl regex="true">^pkg:maven/io\.netty/netty@3.10.6.Final$</packageUrl>
<cve>CVE-2019-16869</cve>
Expand All @@ -268,12 +260,63 @@
<cve>CVE-2021-43797</cve> <!-- We don't decode user HTTP requests nor forward them to remote systems, we also don't support for java 6 or lower - https://github.com/advisories/GHSA-wx5j-54mm-rqqq -->
<cve>CVE-2022-24823</cve> <!-- We don't decode user HTTP requests nor forward them to remote systems, we also don't support for java 6 or lower - https://github.com/advisories/GHSA-269q-hmxg-m83q -->
<cve>CVE-2022-41881</cve>
<cve>CVE-2023-34462</cve> <!-- Suppressed since netty requests in Druid are internal, and not user-facing -->
<cve>CVE-2023-34462</cve> <!-- Suppressed since netty requests in Druid are internal, and not user-facing -->
<!--
The CVEs below are suppressed only for the Netty 3 artifact selected by the packageUrl above. These
advisories affect Netty 4 module artifacts, but Dependency-Check also matches them to the monolithic Netty 3
artifact through the generic netty:netty CPE. Keep the CVEs explicit so that future Netty advisories remain
visible and can be assessed independently.
-->
<cve>CVE-2024-29025</cve>
<cve>CVE-2024-47535</cve>
<cve>CVE-2025-25193</cve>
<cve>CVE-2025-55163</cve> <!-- Netty 3.x not affected; HTTP/2 issues only in 4.x -->
<cve>CVE-2025-58056</cve>
<cve>CVE-2025-58057</cve> <!-- Netty 3.x not affected; compression issue only in 4.x -->
<cve>CVE-2025-67735</cve>
<cve>CVE-2026-33870</cve> <!-- We don't use HttpPostRequestDecoder -->
<cve>CVE-2026-33871</cve> <!-- Netty 3.x not affected; HTTP/2 issues only in 4.x -->
<cve>CVE-2026-41417</cve>
<cve>CVE-2026-42578</cve>
<cve>CVE-2026-42579</cve>
<cve>CVE-2026-42580</cve>
<cve>CVE-2026-42581</cve>
<cve>CVE-2026-42583</cve>
<cve>CVE-2026-42584</cve>
<cve>CVE-2026-42585</cve>
<cve>CVE-2026-42586</cve>
<cve>CVE-2026-42587</cve>
<cve>CVE-2026-44248</cve>
<cve>CVE-2026-44249</cve>
<cve>CVE-2026-44250</cve>
<cve>CVE-2026-44890</cve>
<cve>CVE-2026-44891</cve>
<cve>CVE-2026-44893</cve>
<cve>CVE-2026-45416</cve>
<cve>CVE-2026-45536</cve>
<cve>CVE-2026-45673</cve>
<cve>CVE-2026-45674</cve>
<cve>CVE-2026-46340</cve>
<cve>CVE-2026-47244</cve>
<cve>CVE-2026-47691</cve>
<cve>CVE-2026-48006</cve>
<cve>CVE-2026-48043</cve>
<cve>CVE-2026-48059</cve>
<cve>CVE-2026-50010</cve>
<cve>CVE-2026-50011</cve>
<cve>CVE-2026-50020</cve>
<cve>CVE-2026-50560</cve>
<cve>CVE-2026-56816</cve>
<cve>CVE-2026-56820</cve>
<cve>CVE-2026-56821</cve> <!-- Netty 3.x not affected; OCSP response freshness issue only in Netty 4.x -->
<cve>CVE-2026-56822</cve> <!-- Netty 3.x not affected; OCSP validation race only in Netty 4.x -->
<cve>CVE-2026-59898</cve> <!-- Netty 3.x not affected; WebSocket issue only in Netty 4.x -->
<cve>CVE-2026-59899</cve> <!-- Netty 3.x not affected; HTTP content encoder issue only in Netty 4.x -->
<cve>CVE-2026-59900</cve> <!-- Netty 3.x not affected; HTTP/2 issue only in Netty 4.x -->
<cve>CVE-2026-59901</cve> <!-- Netty 3.x not affected; Bzip2 decoder issue only in Netty 4.x -->
<cve>CVE-2026-59919</cve> <!-- Netty 3.x not affected; HAProxy codec issue only in Netty 4.x -->
<cve>CVE-2026-59920</cve> <!-- Netty 3.x not affected; STOMP codec issue only in Netty 4.x -->
<cve>CVE-2026-59921</cve> <!-- Netty 3.x not affected; multipart filename issue only in Netty 4.x -->
</suppress>

<suppress>
Expand Down Expand Up @@ -345,7 +388,24 @@
</suppress>

<suppress>
<!-- (ranger, ambari, and aliyun-oss) these vulnerabilities are legit, but their latest releases still use the vulnerable jackson version -->
<notes><![CDATA[
web-console uses uuid v4() only to generate query IDs. GHSA-w5hq-g745-h8pq
(CVE-2026-41907) affects the v3/v5/v6 buffer APIs; v4 is not affected.
Revisit this suppression when uuid is upgraded.
]]></notes>
<packageUrl regex="true">^pkg:npm/uuid@7\.0\.3$</packageUrl>
<vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
<cve>CVE-2026-41907</cve>
</suppress>

<suppress>
<!--
These vulnerabilities are legitimate, but the latest releases of ranger, ambari, and aliyun-oss still use
the vulnerable Jackson version. ambari-metrics-common:2.7.0.0.0 is the latest published release and shades
Jackson 1.9.13 into org.apache.ambari.metrics.sink.relocated.jackson, which is used by the timeline sink at
runtime. ambari-metrics-emitter excludes the unrelocated jackson-xc artifact; retain these explicit entries
until ambari-metrics-common can be replaced with a compatible dependency.
-->
<notes><![CDATA[
file name: jackson-xc-1.9.x.jar or jackson-jaxrs-1.9.x.jar
]]></notes>
Expand Down
11 changes: 0 additions & 11 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,6 @@
<jetty.version>12.1.11</jetty.version>
<jersey.version>1.19.4</jersey.version>
<jackson.version>2.22.1</jackson.version>
<codehaus.jackson.version>1.9.13</codehaus.jackson.version>
<log4j.version>2.26.1</log4j.version>
<mysql.version>8.2.0</mysql.version>
<mariadb.version>2.7.3</mariadb.version>
Expand Down Expand Up @@ -1160,16 +1159,6 @@
<artifactId>metrics-core</artifactId>
<version>${dropwizard.metrics.version}</version>
</dependency>
<dependency>
<groupId>org.codehaus.jackson</groupId>
<artifactId>jackson-core-asl</artifactId>
<version>${codehaus.jackson.version}</version>
</dependency>
<dependency>
<groupId>org.codehaus.jackson</groupId>
<artifactId>jackson-mapper-asl</artifactId>
<version>${codehaus.jackson.version}</version>
</dependency>
<dependency>
<groupId>javax.servlet</groupId>
<artifactId>javax.servlet-api</artifactId>
Expand Down
Loading