Skip to content

FasterXML jackson-databind 代码问题漏洞(CVE-2022-42003) #2950

@xiegang666

Description

@xiegang666

最新sentinel-dashboard1.8.6
中jackson-databind 版本是jackson-databind-2.12.6.1.jar

有处理此漏洞的计划吗?

CVE编号
CVE-2022-42003
披露时间
2022-10-02

修复方案
建议受影响客户升级到2.14.0-rc2及以上安全版本,版本获取链接:
https://github.com/FasterXML/jackson-databind

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filegood first issueGood for newcomers

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions