Uploaded image for project: 'TinkerPop'
  1. TinkerPop
  2. TINKERPOP-2355

Jackson-databind version in Gremlin shaded dependency needs to be increased - introduces vulnerability issues

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 3.4.6
    • 3.3.11, 3.4.7
    • build-release
    • None

    Description

      Hello colleagues,

      Encountering the following vulnerabilities during Vulas scan when Tinkerpop 3.4.6 =>

      • FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
      • FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
      • FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
      • FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
      • FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

       
      Vulnerability Id: CVE-2019-20330
      Description: FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

      References: 

      Probably a change similar to this one (https://github.com/apache/tinkerpop/pull/1220/files) , but applying 2.10.2 will resolve the vulnerabilities.

      Thanks in advance for the help!

      Best Regards,
      Simeon Andonov

      Attachments

        Issue Links

          Activity

            People

              spmallette Stephen Mallette
              SimeonAndonov Simeon Andonov
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: