Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump jackson-databind from 2.13.3 to 2.13.4.2 #738

Closed
wants to merge 5 commits into from

Conversation

wkurniawan07
Copy link
Contributor

@wkurniawan07 wkurniawan07 commented Jan 23, 2023

Fixes

Updates jackson-related libraries to 2.13.4 or 2.13.4.2 (latest version for 2.13). This mitigates CVE-2022-42003 and CVE-2022-42002.

@rogierslag
Copy link

We'd also be interested in this release, as Jackson 2.13.3 has 3 open CVEs

Note that 2.13.4.2 is still vulnerable for the last one, best would be an update to 2.16.1

@tiwarishubham635
Copy link
Contributor

Hello! I am from twilio and I have looked at this PR. I created #745 that will be addressing this issue. Closing this PR here. Please create a new issue if further assistance is needed. Thanks!

@wkurniawan07 wkurniawan07 deleted the jackson-version branch January 18, 2024 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants