Skip to content
This repository was archived by the owner on Apr 1, 2025. It is now read-only.

Updated jackson-databind to address vulnerability#7

Merged
dustygraham merged 1 commit intoSignalPath:masterfrom
benjaminjacobberg:master
Mar 5, 2021
Merged

Updated jackson-databind to address vulnerability#7
dustygraham merged 1 commit intoSignalPath:masterfrom
benjaminjacobberg:master

Conversation

@benjaminjacobberg
Copy link
Copy Markdown

Introduced through: com.fasterxml.jackson.core:jackson-databind@2.10.3 and org.json4s:json4s-jackson_2.13@3.6.7
Fixed in: com.fasterxml.jackson.core:jackson-databind@2.6.7.4, @2.9.10.7, @2.10.5.1

Introduced through: project@1.0.0-SNAPSHOT › com.fasterxml.jackson.core:jackson-databind@2.10.3
Remediation: Upgrade to com.fasterxml.jackson.core:jackson-databind@2.10.5.1
Introduced through: project@1.0.0-SNAPSHOT › org.json4s:json4s-jackson_2.13@3.6.7 › com.fasterxml.jackson.core:jackson-databind@2.10.3
Vulnerable Functions
com/fasterxml/jackson/databind/ext/DOMSerializer.

Overview
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor.

Affected versions of this package are vulnerable to XML External Entity (XXE) Injection. A flaw was found in FasterXML Jackson Databind, where it does not have entity expansion secured properly in the DOMDeserializer class. The highest threat from this vulnerability is data integrity.

@dustygraham dustygraham merged commit 69a92ec into SignalPath:master Mar 5, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants