Hello, our container scanning tool detects some (a...
# general
o
Hello, our container scanning tool detects some (almost 20) critical VUL concerning jackson-bind... (ex: CVE-2017-15095 in apache/druid29.0.1com.fasterxml.jackson.core:jackson-databind) with the 29.0.1... They are not in the owasp-dependency-check-suppressions.xml so are there legit ? How to tackle that ?
n
Hey I asked a similar question a few days ago Seems that there is no solution at the moment and you can try to build Druid yourself to overcome this https://apachedruidworkspace.slack.com/archives/C0303FDCZEZ/p1713260572000489