<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Databricks-jdbc and vulnerabilities CVE-2022-42004, CVE-2022-42003 in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28354#M20174</link>
    <description>&lt;P&gt;Hi @Lars Joreteg​&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does @Hubert Dudek​&amp;nbsp; response answer your question? If yes, would you be happy to &lt;B&gt;mark it as best &lt;/B&gt;so that other members can find the solution more quickly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'd love to hear from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Nov 2022 05:06:46 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2022-11-17T05:06:46Z</dc:date>
    <item>
      <title>Databricks-jdbc and vulnerabilities CVE-2022-42004, CVE-2022-42003</title>
      <link>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28352#M20172</link>
      <description>&lt;P&gt;The latest version of Databricks-jdbc available through Maven (2.6.29) now has these two vulnerabilities:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2022-42004" alt="https://nvd.nist.gov/vuln/detail/CVE-2022-42004" target="_blank"&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-42004&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2022-42003" alt="https://nvd.nist.gov/vuln/detail/CVE-2022-42003" target="_blank"&gt;https://nvd.nist.gov/vuln/detail/CVE-2022-42003&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;All due to depending on and including in the jar the library j&lt;B&gt;ackson-databind 2.13.2.2&lt;/B&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a possibility to have a new updated version of &lt;B&gt;Databricks-jdbc&lt;/B&gt; that uses &lt;B&gt;jackson 2.14.0-rc1&lt;/B&gt;? (the currently only jackson-databind version that passes the two vulnerability checks above)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently using the databricks-jdbc driver in an environment where we can only get an exception for this that lasts a short time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also - If databricks-jdbc was available in thin form on Maven, we would be able to fix it ourselves. Is that possible to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! - Lars&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 21:04:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28352#M20172</guid>
      <dc:creator>Lars_J</dc:creator>
      <dc:date>2022-10-07T21:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks-jdbc and vulnerabilities CVE-2022-42004, CVE-2022-42003</title>
      <link>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28353#M20173</link>
      <description>&lt;P&gt;I think you need to contact support or your sales representative from Databricks.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 10:26:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28353#M20173</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2022-10-16T10:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks-jdbc and vulnerabilities CVE-2022-42004, CVE-2022-42003</title>
      <link>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28354#M20174</link>
      <description>&lt;P&gt;Hi @Lars Joreteg​&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does @Hubert Dudek​&amp;nbsp; response answer your question? If yes, would you be happy to &lt;B&gt;mark it as best &lt;/B&gt;so that other members can find the solution more quickly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'd love to hear from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 05:06:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/databricks-jdbc-and-vulnerabilities-cve-2022-42004-cve-2022/m-p/28354#M20174</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-11-17T05:06:46Z</dc:date>
    </item>
  </channel>
</rss>

