Skip to content

Commit

Permalink
CVE-2020-36518: Bump jackson-databind to 2.13.2.2
Browse files Browse the repository at this point in the history
This resolves #4145, the jackson-databind CVE.
A similar patch is also made in swagger-parser (swagger-parser#1690)
  • Loading branch information
lmr3796 authored Apr 1, 2022
1 parent 0a16eb7 commit 2ddb152
Showing 1 changed file with 6 additions and 1 deletion.
7 changes: 6 additions & 1 deletion pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -568,7 +568,7 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson-version}</version>
<version>${jackson-databind-version}</version>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
Expand Down Expand Up @@ -656,6 +656,11 @@
<jersey2-version>2.26</jersey2-version>
<junit-version>4.13.1</junit-version>
<jackson-version>2.13.2</jackson-version>
<!--
jackson-databind 2.13.2 is still affected by CVE-2020-36518.
This version pin for jackson-databind can be removed when bumping jackson to 2.14
-->
<jackson-databind-version>2.13.2.2</jackson-databind-version>
<logback-version>1.2.9</logback-version>
<classgraph-version>4.8.138</classgraph-version>
<guava-version>31.0.1-jre</guava-version>
Expand Down

0 comments on commit 2ddb152

Please sign in to comment.