Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential issue with jackson-databind 2.9.9.x #2128

Closed
AnEmortalKid opened this issue Aug 6, 2019 · 1 comment
Closed

Potential issue with jackson-databind 2.9.9.x #2128

AnEmortalKid opened this issue Aug 6, 2019 · 1 comment

Comments

@AnEmortalKid
Copy link

[CVE-2019-14379](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14379

Is being flagged for jackson-databind-xml:

cpe: cpe:/a:fasterxml:jackson:2.9.9  Confidence:Low  suppress
maven: com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.9.9  Confidence:Highest
cpe: cpe:/a:fasterxml:jackson-databind:2.9.9  Confidence:Highest  suppress
jackson-dataformat-xml-2.9.9.jar (cpe:/a:fasterxml:jackson:2.9.9, com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.9.9, cpe:/a:fasterxml:jackson-databind:2.9.9) : CVE-2019-14379, CVE-2019-12814

The CVE's were assessed and fixed in the jackson-databind module and not databind-xml: FasterXML/jackson-dataformat-xml#349
FasterXML/jackson-databind#2387

I wasn't entirely sure if this fell under the false positive/negative category or there's something missing that would help associate the 2.9.9.x versions as fixed.

Plugin Version in use:

dependency-check-maven:4.0.2:check
@jeremylong
Copy link
Owner

The referenced CVE is not fixed in 2.9.9 - it is fixed in 2.9.9.2. Using ODC 5.2.1 these are correctly reported.

@lock lock bot locked and limited conversation to collaborators Oct 21, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants