Recent GHSAs from Jackson are not available in global GHSA database #6050
beth-soptim
started this conversation in
General
Replies: 3 comments 2 replies
-
|
@beth-soptim You'll have to ask GitHub. |
Beta Was this translation helpful? Give feedback.
2 replies
-
|
Once CVEs publish (which I understand should be done by Github), we should be good? |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Finally they are now available in the GHSA database:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment

Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
is there any special reason why the recent security issues in Jackson only have GHSAs inside the Jackson project [1] but not in the "global" GHSA database [2]?
Thus, many vulnerability scanners will not detect these issues.
[1] https://github.com/FasterXML/jackson-databind/security/advisories
[2] https://github.com/github/advisory-database
Beta Was this translation helpful? Give feedback.
All reactions