Skip to content

Fix the jackson-databind vul for deserialization of untrusted data. - #1240

Closed
berngp wants to merge 1 commit into
docker-java:masterfrom
berngp:feature/fix-jackson-databind-vul
Closed

Fix the jackson-databind vul for deserialization of untrusted data.#1240
berngp wants to merge 1 commit into
docker-java:masterfrom
berngp:feature/fix-jackson-databind-vul

Conversation

@berngp

@berngp berngp commented Sep 5, 2019

Copy link
Copy Markdown

This commit upgrades the dependency of jackson-databind to address the
Deserialization of Untrusted Data vulnerability as documented in
Ref. https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617

This is affecting com.fasterxml.jackson.core:jackson-databind artifact, versions [,2.9.9.3)


This change is Reviewable

This commit upgrades the dependency of jackson-databind to address the
Deserialization of Untrusted Data vulnerability as documented in
Ref. https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617

This is affecting com.fasterxml.jackson.core:jackson-databind artifact, versions [,2.9.9.3)
@bsideup

bsideup commented Feb 17, 2020

Copy link
Copy Markdown
Member

@berngp could you please rebase?

@KostyaSha

Copy link
Copy Markdown
Member

Closed via #1344

@KostyaSha KostyaSha closed this Mar 10, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants