4 ms·
jackson-databind is the name of the package on Fedora and on RHEL. We addressed this issue last week by updating to 2.10, though I think F30 and F31 updates sti
by cipherboy 7y ago
jackson-databind is the name of the package on Fedora and on RHEL. We addressed this issue last week by updating to 2.10, though I think F30 and F31 updates still needs karma [0].
The other jackson packages are mostly Java package hierarchy that don't affect this CVE (jackson-core, jackson-bom, jackson-parent, and jackson-annotations -- but we've also updated all of these to 2.10 on F30+).
So:
rpm -qa | grep jackson-databind
To the GGP:
As noted by other commenters just having the package isn't sufficient. You need a number of other libraries (most of which aren't shipped with Fedora, none of which are shipped on RHEL) on the classpath of the running JVM.
If you're not running any Java code, you're definitely not affected. If you're using any code distributed through the official channels, it is very unlikely that you're affected. You'll probably only be affected if you're using third-party projects. Which as always, are run at your own risk. :)
[0]: Source: co-maintainer of the package via the Fedora Stewardship SIG.
F30 Bodhi: https://bodhi.fedoraproject.org/updates/FEDORA-2019-b171554877 https://bodhi.fedoraproject.org/updates/FEDORA-2019-b1715548...
F31 Bodhi: https://bodhi.fedoraproject.org/updates/FEDORA-2019-cf87377f5f https://bodhi.fedoraproject.org/updates/FEDORA-2019-cf87377f...