Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency to jackson library due to CVE-2022-42003 and CVE-2022-42004 #624

Closed
uap-universe opened this issue Oct 19, 2022 · 3 comments

Comments

@uap-universe
Copy link

Please update the dependency

com.fasterxml.jackson.core:jackson-databind:2.13.2.2

to

com.fasterxml.jackson.core:jackson-databind:2.14

as soon as it becomes available

(see also: related issue and milestone)

@brackxm
Copy link

brackxm commented Oct 19, 2022

2.13.4.1 is available with a fix for CVE-2022-42003
see https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13

(and 2.13.4.2 is available also)

@jimmyjames
Copy link
Contributor

Thanks @brackxm. We have made #631 and #630 to bump the versions. We will get patch releases out shortly.

@jimmyjames
Copy link
Contributor

4.2.1 and 3.19.3 have been released and are available in Maven Central 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants