Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Jackson 2.9.10.20200223 to address CVE-2020-8840 #3168

Merged
merged 1 commit into from Feb 23, 2020

Conversation

joschi
Copy link
Member

@joschi joschi commented Feb 23, 2020

@joschi joschi added this to the 1.3.20 milestone Feb 23, 2020
@joschi joschi requested a review from a team February 23, 2020 14:54
@joschi joschi self-assigned this Feb 23, 2020
@joschi joschi merged commit 3b029a5 into release/1.3.x Feb 23, 2020
@joschi joschi deleted the jackson-2.9.10.20200223 branch February 23, 2020 15:28
@msymons
Copy link
Contributor

msymons commented Feb 24, 2020

@joschi, fast work with the commit! jackson-bom 2.9.10.20200223 had only been in maven for few hours!

However, CVE-2020-8840 did start alerting yesterday in scanners that use OSS Index as a data source. So, any idea when 1.3.20 will be released?

@jplock
Copy link
Member

jplock commented Feb 24, 2020

@msymons it was released earlier today - https://github.com/dropwizard/dropwizard/releases/tag/v1.3.20

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants