Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use a vuln free version of fasterxml #242

Open
mpatnode opened this issue Mar 25, 2022 · 1 comment
Open

Use a vuln free version of fasterxml #242

mpatnode opened this issue Mar 25, 2022 · 1 comment

Comments

@mpatnode
Copy link

Though it may not be exploitable, the noise created by Snyk image scans which contain the agent would be very nice to fix.

Name : com.fasterxml.jackson.dataformat:jackson-dataformat-cbor
Version : 0:2.10.3
File path : usr/share/aws-kinesis-agent/lib/jackson-dataformat-cbor-2.10.3.jar

https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329

@mpatnode
Copy link
Author

If anyone is interested in helping me test this change, you can grab the RPM (or code) here: https://github.com/britive/amazon-kinesis-agent/raw/master/rpm/aws-kinesis-agent-2.0.6-1b.amzn2.noarch.rpm Unfortunately, it's not clear to me how to setup and run the test suite.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant