Hemant.Rumde_183868 avatar image
Hemant.Rumde_183868 asked smadhavan commented

DSE includes a version of Jackson-databind package identified as vulnerable to RCE in CVE-2020-8840

DSE jar is using Jackson-databind library. Twistlock informed critical vulnerabilities for the Jackson-databind version used in DSE. I tried to use different version by dependency in pom.xml

However DSE is not using the secured version suggested by twistlock report. Is it tightly coupled with the older version? This critical vulnerability is blocking deployment in K8S cluster.

I tried following dependencies


Can you provide us pom dependencies to remove existing vulnerabilities?

1 comment
10 |1000

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

smadhavan avatar image smadhavan ♦ commented ·

@Hemant.Rumde_183868, one other thing to note is when you're leveraging the Unified Java Driver,


you should not be needing to add any other dependencies like as below as it is already included part of the Unified Java Driver,

0 Likes 0 ·

1 Answer

Erick Ramirez avatar image
Erick Ramirez answered Erick Ramirez edited


DataStax Enterprise ships with the Jackson databind package -- a general-purpose data-binding functionality and tree-model for the Jackson Data Processor.

The latest version DSE 6.8.1 (at the time of writing) ships with Jackson databind v2.9.10.2 (jackson-databind- which has been flagged as vulnerable to remote code execution (RCE) as disclosed in the National Vulnerability Database (NVD) as vulnerability CVE-2020-8840.

Patched releases

The Jackson databind project patched issue #2620 to address the vulnerability in version

The next planned release of DSE 6.8 is tabled to ship with Jackson databind version (internal DataStax ID DSP-20981).


I have noted that you already engaged DataStax Support directly and our engineers will provide you the relevant updates. Specifically on your question, updating the pom.xml is not relevant since the dependency is internal to DSE. The update will be provided in the next release of DSE 6.8.

For the benefit of other Community members watching this post, I will provide an update when a new version of DSE 6.8 gets released in the coming weeks. We are not in a position to provide an ETA at this point. Cheers!

10 |1000

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.