Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2020-36518: Bump jackson-databind to 2.13.2.2 #4155

Merged
merged 1 commit into from Apr 4, 2022

Conversation

lmr3796
Copy link
Contributor

@lmr3796 lmr3796 commented Apr 1, 2022

This resolves #4145, the jackson-databind CVE.
A similar patch is also made in swagger-parser (swagger-parser#1690)

This resolves swagger-api#4145, the jackson-databind CVE.
A similar patch is also made in swagger-parser (swagger-parser#1690)
@lmr3796
Copy link
Contributor Author

lmr3796 commented Apr 1, 2022

Hi @frantuma would you mind taking a look at this?

We got alerted for vulnerability as we transitively pulls in swagger, so we decided to contribute a fix to this.

@lmr3796
Copy link
Contributor Author

lmr3796 commented Apr 1, 2022

CC'ing @efeg This is also on the dep chain.

@macfarla
Copy link

macfarla commented Apr 3, 2022

we also got alerted for this vulnerability in our project. Would be great to see a new release with this fix.

@frantuma frantuma merged commit d353c3b into swagger-api:master Apr 4, 2022
@frantuma
Copy link
Member

frantuma commented Apr 4, 2022

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE-2020-36518 (High) detected in jackson-databind-2.13.2.jar
3 participants