New Contributor
Posts: 5
Registered: ‎06-16-2015

Security exposure and impacts of CVE-2017-7525

The CVE-2017-7525 was reported some time ago :

The vulnerability is found in multiple versions of jackson-databind.


Since jackson-databind is a direct dependecy of Spark and other bigdata Apache projects, these projects are surely impacted by this vulnerability.


Did you evaluate the security exposure of this vulnerability on CDH ? Was it fixed in new minor versions ?