Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUN-805: CVE-2020-36518 fix (recreate 7626) #7628

Merged
merged 2 commits into from
Apr 4, 2022
Merged

RUN-805: CVE-2020-36518 fix (recreate 7626) #7628

merged 2 commits into from
Apr 4, 2022

Conversation

gschueler
Copy link
Member

(Recreate #7626 for CI)

  • Also used jackson-bom.version to bump jackson-core

original:

Is this a bugfix, or an enhancement? Please describe.

It's a bugfix that addresses multiple security vulnerabilities:

Describe the solution you've implemented

I've bumped the version numbers of:

  • com.fasterxml.jackson.core:jackson-databind
  • com.fasterxml.jackson.dataformat:jackson-dataformat-cbor

I also created a separate property for jackson-dataformat-cbor.

Describe alternatives you've considered
N/A

Additional context

https://nvd.nist.gov/vuln/detail/CVE-2020-36518

root and others added 2 commits April 4, 2022 10:49
Bump versions and create a new property to address a vuln that exists only in Jackson Databind.
@gschueler gschueler added this to the 4.1.0 milestone Apr 4, 2022
@mergify mergify bot added the 4.x label Apr 4, 2022
@gschueler gschueler modified the milestone: 4.1.0 Apr 4, 2022
@gschueler gschueler merged commit c86dcff into main Apr 4, 2022
@gschueler gschueler deleted the RUN-805 branch April 4, 2022 23:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant