Skip to content

Commit af56171

Browse files
committed
Update dependency of jackson to 2.9.9
Update the Jackson libraries used from 2.9.8 to current 2.9.9 due to CVE-2019-12086 in Jackson-Databind. Bugzilla Id: 63473 git-svn-id: https://svn.apache.org/repos/asf/jmeter/trunk@1860342 13f79535-47bb-0310-9956-ffa450edef68 Former-commit-id: 62ce6f3
1 parent de29acd commit af56171

6 files changed

Lines changed: 21 additions & 19 deletions

File tree

LICENSE

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -251,9 +251,9 @@ The following software is provided under the Apache License V 2.0 (as above):
251251
* caffeine-2.6.2.jar
252252
* darcula.jar
253253
* freemarker-2.3.28.jar (AL2.0, see licenses/bin for additional info)
254-
* jackson-annotations-2.9.8.jar
255-
* jackson-core-2.9.8.jar
256-
* jackson-databind-2.9.8.jar
254+
* jackson-annotations-2.9.9.jar
255+
* jackson-core-2.9.9.jar
256+
* jackson-databind-2.9.9.jar
257257
* json-path-2.4.0.jar
258258
* json-smart-2.3.jar
259259
* mongo-java-driver-2.11.3.jar

build.properties

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -210,20 +210,20 @@ httpcore-nio.jar = httpcore-nio-${httpcore-nio.version}.jar
210210
httpcore-nio.loc = ${maven2.repo}/org/apache/httpcomponents/httpcore-nio/${httpcore-nio.version}
211211
httpcore-nio.sha512 = 921BFA77D06C2B624D257DC6D57689A06F704954AE49FE4433D5200018F46607A46EA21ECA3C7757913BD6C1C2605A025BEA912A007230EA2E4227C07F8ADCA3
212212

213-
jackson-annotations.version = 2.9.8
213+
jackson-annotations.version = 2.9.9
214214
jackson-annotations.jar = jackson-annotations-${jackson-annotations.version}.jar
215215
jackson-annotations.loc = ${maven2.repo}/com/fasterxml/jackson/core/jackson-annotations/${jackson-annotations.version}
216-
jackson-annotations.sha512 = 05A7A203623DF2E7A2C338D589871C07258E7552F4C55B3F45BBBD77B5E04B7A77F96779F19394182B20DE98DB419496AB0ADB6D5D28C42F8FFEA1C76C82D8AF
216+
jackson-annotations.sha512 = fd7e441fbb6a807b1841497bbf6b4950ca11a48fad19b83bad6da691a9878a8b03f28eef11dac7ef160cb9535c999d7bbf49da155c165c205aeb7dd81c111f28
217217

218-
jackson-core.version = 2.9.8
218+
jackson-core.version = 2.9.9
219219
jackson-core.jar = jackson-core-${jackson-core.version}.jar
220220
jackson-core.loc = ${maven2.repo}/com/fasterxml/jackson/core/jackson-core/${jackson-core.version}
221-
jackson-core.sha512 = 695C4BF0C5BF72910DC09CD6062FAA7690ECE110F874DADE86D5E3D6EE5598E57572517200D7A31816AB599F01350E5AAC9A671FFB826650F385EA97E4BC0D98
221+
jackson-core.sha512 = d8beac9e71444bc795c9d99308ead3284a39aa161f825708da7dbdfce410d099c0bbc76c31c27adad540cf3bccf6826d539fcb157923efae84b10b3778b920a9
222222

223-
jackson-databind.version = 2.9.8
223+
jackson-databind.version = 2.9.9
224224
jackson-databind.jar = jackson-databind-${jackson-databind.version}.jar
225225
jackson-databind.loc = ${maven2.repo}/com/fasterxml/jackson/core/jackson-databind/${jackson-databind.version}
226-
jackson-databind.sha512 = 720F2D2779CBFD4B470CB5106AB3944EF12717330534B94F99D8D81D1F07BBA809A30BC92E296ECB31CB76C2FEAA06870B7EDFF5A081C7EFED9C3AC7E5CEBE2F
226+
jackson-databind.sha512 = 47204158c4adbbc8d6659055786641ef6ec95ef6648662ad797aface0a3e1074c7bd4d2f565bbe5837bfd0bc06aec2d8888415ff94a94583f5bda644ca5004a5
227227

228228
jakarta-oro.version = 2.0.8
229229
jakarta-oro.jar = oro-${jakarta-oro.version}.jar

eclipse.classpath

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -74,9 +74,9 @@
7474
<classpathentry kind="lib" path="lib/httpcore-nio-4.4.11.jar"/>
7575
<classpathentry kind="lib" path="lib/httpcore-4.4.11.jar"/>
7676
<classpathentry kind="lib" path="lib/httpmime-4.5.8.jar"/>
77-
<classpathentry kind="lib" path="lib/jackson-annotations-2.9.8.jar"/>
78-
<classpathentry kind="lib" path="lib/jackson-core-2.9.8.jar"/>
79-
<classpathentry kind="lib" path="lib/jackson-databind-2.9.8.jar"/>
77+
<classpathentry kind="lib" path="lib/jackson-annotations-2.9.9.jar"/>
78+
<classpathentry kind="lib" path="lib/jackson-core-2.9.9.jar"/>
79+
<classpathentry kind="lib" path="lib/jackson-databind-2.9.9.jar"/>
8080
<classpathentry kind="lib" path="lib/javax.activation-api-1.2.0.jar"/>
8181
<classpathentry kind="lib" path="lib/javax.activation-1.2.0.jar"/>
8282
<classpathentry kind="lib" path="lib/jcharts-0.7.5.jar"/>

lib/aareadme.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -123,14 +123,14 @@ javax.activation-1.2.0.jar
123123
----------------------
124124
- used by SMTP Sampler
125125

126-
jackson-annotations-2.9.8 (com.fasterxml.jackson)
126+
jackson-annotations-2.9.9 (com.fasterxml.jackson)
127127
----------------------
128128

129129
Used by JsonExporter in report generator (com.fasterxml.jackson)
130130
----------------------
131-
jackson-annotations-2.9.8 (https://github.com/FasterXML/jackson-annotations)
132-
jackson-core-2.9.8 (https://github.com/FasterXML/jackson-core)
133-
jackson-databind-2.9.8 (https://github.com/FasterXML/jackson-databind)
131+
jackson-annotations-2.9.9 (https://github.com/FasterXML/jackson-annotations)
132+
jackson-core-2.9.9 (https://github.com/FasterXML/jackson-core)
133+
jackson-databind-2.9.9 (https://github.com/FasterXML/jackson-databind)
134134

135135
jCharts-0.7.5 (org.jCharts)
136136
-------------

res/maven/ApacheJMeter_parent.pom

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -82,9 +82,9 @@ under the License.
8282
<httpcore.version>4.4.11</httpcore.version>
8383
<httpcore-nio.version>4.4.11</httpcore-nio.version>
8484
<httpmime.version>4.5.8</httpmime.version>
85-
<jackson-annotations.version>2.9.8</jackson-annotations.version>
86-
<jackson-core.version>2.9.8</jackson-core.version>
87-
<jackson-databind.version>2.9.8</jackson-databind.version>
85+
<jackson-annotations.version>2.9.9</jackson-annotations.version>
86+
<jackson-core.version>2.9.9</jackson-core.version>
87+
<jackson-databind.version>2.9.9</jackson-databind.version>
8888
<jakarta-oro.version>2.0.8</jakarta-oro.version>
8989
<javax.activation-api.version>1.2.0</javax.activation-api.version>
9090
<javax.activation.version>1.2.0</javax.activation.version>

xdocs/changes.xml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -126,6 +126,7 @@ to view the last major behaviors with the version 5.1.1.
126126
<ch_section>Non-functional changes</ch_section>
127127
<ul>
128128
<li>Updated to tika-core and tika-parsers 1.21 (from 1.21)</li>
129+
<li>Updated jackson-annotations, jackson-core and jackson-databind to 2.9.9 (from 2.9.8)</li>
129130
</ul>
130131

131132
<!-- =================== Bug fixes =================== -->
@@ -202,6 +203,7 @@ to view the last major behaviors with the version 5.1.1.
202203
<li>Sergiy Iampol (sergiy.iampol at playtech.com)</li>
203204
<li>Brian Tully (brian.tully at acquia.com)</li>
204205
<li>Amer Ghazal (amerghazal at gmail.com)</li>
206+
<li>(stefan at trilobyte-se.de)</li>
205207
</ul>
206208
<p>
207209
Apologies if we have omitted anyone else.

0 commit comments

Comments
 (0)