Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency com.fasterxml.jackson.core:jackson-databind to v2.12.7.1 - autoclosed #15

Conversation

dev-mend-for-github-com[bot]
Copy link

@dev-mend-for-github-com dev-mend-for-github-com bot commented Apr 29, 2023

This PR contains the following updates:

Package Type Update Change
com.fasterxml.jackson.core:jackson-databind (source) compile minor 2.9.10.4 -> 2.12.7.1

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
Critical 9.8 CVE-2015-4473 #68
Critical 9.8 CVE-2019-17571 #67
High 8.1 CVE-2020-14060

High 8.1 CVE-2020-14061

High 8.1 CVE-2020-14062

High 8.1 CVE-2020-14195

High 8.1 CVE-2020-24616

High 8.1 CVE-2020-24750

High 8.1 CVE-2020-35490

High 8.1 CVE-2020-35491

High 8.1 CVE-2020-35728

High 8.1 CVE-2020-36179

High 8.1 CVE-2020-36180

High 8.1 CVE-2020-36181

High 8.1 CVE-2020-36182

High 8.1 CVE-2020-36183

High 8.1 CVE-2020-36184

High 8.1 CVE-2020-36185

High 8.1 CVE-2020-36186

High 8.1 CVE-2020-36187

High 8.1 CVE-2020-36188

High 8.1 CVE-2020-36189

High 8.1 CVE-2021-20190

High 7.5 CVE-2020-25649

High 7.5 CVE-2020-36518 #69
High 7.5 CVE-2022-42003 #66
High 7.5 CVE-2022-42004 #65
Medium 5.5 CVE-2018-7273 #63
Medium 5.3 WS-2017-3734


  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com bot added the security fix Security fix generated by Mend label Apr 29, 2023
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/com.fasterxml.jackson.core-jackson-databind-2.x branch from f33d412 to 8b5a81e Compare April 29, 2023 06:39
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency com.fasterxml.jackson.core:jackson-databind to v2.9.10.8 Update dependency com.fasterxml.jackson.core:jackson-databind to v2.12.7.1 Jul 12, 2023
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/com.fasterxml.jackson.core-jackson-databind-2.x branch from 8b5a81e to 768b36a Compare July 12, 2023 01:02
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency com.fasterxml.jackson.core:jackson-databind to v2.12.7.1 Update dependency com.fasterxml.jackson.core:jackson-databind to v2.12.7.1 - autoclosed Jul 27, 2023
@dev-mend-for-github-com dev-mend-for-github-com bot deleted the whitesource-remediate/com.fasterxml.jackson.core-jackson-databind-2.x branch July 27, 2023 06:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants