Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix: updated jackson-databind to 2.9.9.3 to block CVE #347

Merged
merged 2 commits into from
Aug 15, 2019
Merged

Fix: updated jackson-databind to 2.9.9.3 to block CVE #347

merged 2 commits into from
Aug 15, 2019

Conversation

danbrodsky
Copy link
Contributor

@danbrodsky danbrodsky commented Jul 15, 2019

Changes

Version bump for jackson-databind dependency to 2.9.9.3

References

#346

@danbrodsky danbrodsky requested a review from a team July 15, 2019 23:13
@joshcanhelp joshcanhelp requested review from jimmyjames and lbalmaceda and removed request for a team August 1, 2019 21:25
@rsclarke-vgw
Copy link

Can this be bumped to 2.9.9.3 for CVE-2019-14379 and CVE-2019-14439?

@danbrodsky danbrodsky changed the title Fix: updated jackson-databind to 2.9.9.1 to block CVE-2019-12814 Fix: updated jackson-databind to 2.9.9.3 to block CVE-2019-12814 Aug 9, 2019
@danbrodsky danbrodsky changed the title Fix: updated jackson-databind to 2.9.9.3 to block CVE-2019-12814 Fix: updated jackson-databind to 2.9.9.3 to block CVE Aug 9, 2019
@lbalmaceda lbalmaceda added this to the v3-Next milestone Aug 9, 2019
@lbalmaceda lbalmaceda removed the request for review from jimmyjames August 9, 2019 18:11
@jimmyjames jimmyjames merged commit 00deb41 into auth0:master Aug 15, 2019
@jimmyjames jimmyjames modified the milestones: v3-Next, 3.8.2 Aug 15, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants