Skip to content

Commit 9de1230

Browse files
committed
Update Jackson to 2.9.9.3
As recommended by https://nvd.nist.gov/vuln/detail/CVE-2019-14379 (Remove unused dependency)
1 parent e987276 commit 9de1230

4 files changed

Lines changed: 3 additions & 6 deletions

File tree

dd-java-agent/instrumentation/elasticsearch/transport-2/transport-2.gradle

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,10 +46,9 @@ dependencies {
4646
testCompile group: 'org.apache.logging.log4j', name: 'log4j-core', version: '2.11.0'
4747
testCompile group: 'org.apache.logging.log4j', name: 'log4j-api', version: '2.11.0'
4848

49-
testCompile group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-smile', version: versions.jackson
49+
testCompile group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-smile', version: '2.9.9'
5050
// ^ is needed because we are using a newer version of jackson that isn't compatible without this.
5151

52-
5352
latestDepTestCompile group: 'org.elasticsearch', name: 'elasticsearch', version: '2.4.6'
5453
latestDepTestCompile group: 'org.springframework.data', name: 'spring-data-elasticsearch', version: '2.1.15.RELEASE'
5554
}

dd-trace-ot/dd-trace-ot.gradle

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,6 @@ dependencies {
3434

3535
compile deps.jackson
3636
compile deps.slf4j
37-
compile group: 'org.msgpack', name: 'jackson-dataformat-msgpack', version: '0.8.16'
3837
compile group: 'com.squareup.okhttp3', name: 'okhttp', version: '3.11.0' // Last version to support Java7
3938
compile group: 'com.github.jnr', name: 'jnr-unixsocket', version: '0.22'
4039
compile group: 'com.lmax', name: 'disruptor', version: '3.4.2'

dd-trace/dd-trace.gradle

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,6 @@ dependencies {
1616

1717
compile deps.slf4j
1818
compile deps.jackson
19-
compile group: 'org.msgpack', name: 'jackson-dataformat-msgpack', version: '0.8.16'
2019

2120
compile project(':utils:gc-utils')
2221

gradle/dependencies.gradle

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ext {
77

88
slf4j : "1.7.25",
99
guava : "20.0", // Last version to support Java 7
10-
jackson : "2.9.9", // https://nvd.nist.gov/vuln/detail/CVE-2019-12086
10+
jackson : "2.9.9.3", // https://nvd.nist.gov/vuln/detail/CVE-2019-14379
1111

1212
spock : "1.3-groovy-$spockGroovyVer",
1313
groovy : groovyVer,
@@ -35,7 +35,7 @@ ext {
3535
guava : "com.google.guava:guava:$versions.guava",
3636
jackson : [
3737
dependencies.create(group: 'com.fasterxml.jackson.core', name: 'jackson-databind', version: versions.jackson),
38-
dependencies.create(group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-yaml', version: versions.jackson),
38+
dependencies.create(group: 'org.msgpack', name: 'jackson-dataformat-msgpack', version: '0.8.17'),
3939
],
4040
bytebuddy : dependencies.create(group: 'net.bytebuddy', name: 'byte-buddy', version: "${versions.bytebuddy}"),
4141
autoservice : [

0 commit comments

Comments
 (0)