Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Jackson 2.9.5 #12638

Closed
wants to merge 1 commit into from
Closed

Upgrade to Jackson 2.9.5 #12638

wants to merge 1 commit into from

Conversation

devnied
Copy link

@devnied devnied commented Mar 26, 2018

Upgrade to jackson 2.9.5 to fix the CVE-2018-7489 (FasterXML/jackson-databind#1931)

Upgrade to jackson 2.9.5 to fix the CVE-2018-7489 in the version 2.9.4
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Mar 26, 2018
@wilkinsona
Copy link
Member

Thanks for the PR. We have a semi-automated process that takes care of dependency upgrades like this. Running that process has just highlighted that many of 2.9.5's modules are not yet in Maven Central. We'll get to this upgrade in due course and before Boot 2.0.1 is released. Thanks anyway.

@wilkinsona wilkinsona closed this Mar 26, 2018
@wilkinsona wilkinsona added status: declined A suggestion or change that we don't feel we should currently apply and removed status: waiting-for-triage An issue we've not yet triaged labels Mar 26, 2018
@sgleske-ias
Copy link

@wilkinsona can you have an open issue that people can subscribe to? And only close it if a new release contains a fix?

@sgleske-ias
Copy link

@sgleske-ias
Copy link

Correction, 2.0.0 release does not have the fix https://github.com/spring-projects/spring-boot/blob/v2.0.0.RELEASE/spring-boot-project/spring-boot-dependencies/pom.xml

Do you mind still having an open issue until a release goes out with a fix?

@philwebb
Copy link
Member

@sgleske-ias Issues are closed when they are fixed, regardless of if a release is out or not. In this case issue #12639 shows the upgrade happened in commit 14b8e75 an is in milestone 2.0.1. The milestone page shows that 2.0.1 is still open and is due to be released on April 5.

@sgleske-ias
Copy link

Thanks for the heads up @philwebb . I'll check back days following April 5th and see what updates are in the project. 👍

@sgleske-ias
Copy link

@philwebb are there any plans to backport the fix to the 1.5 series of spring-boot?

@philwebb
Copy link
Member

@sgleske-ias No 1.5.x will remain on the 2.8.x line of Jackson.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: declined A suggestion or change that we don't feel we should currently apply
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants