Skip to content
This repository has been archived by the owner on Sep 16, 2020. It is now read-only.

Numerous Jackson CVEs affecting SJC #126

Open
pmonks opened this issue Oct 18, 2018 · 0 comments
Open

Numerous Jackson CVEs affecting SJC #126

pmonks opened this issue Oct 18, 2018 · 0 comments

Comments

@pmonks
Copy link
Contributor

pmonks commented Oct 18, 2018

At the time of writing, there are 40 CVEs raised against jackson-databind v2.9.4. They are listed below.

Although it's not a direct dependency, SJC transitively depends on jackson-databind v2.9.4 via jackson-jaxrs-json-provider v2.9.4 and jackson-jaxrs-base v2.9.4.

The CVEs in question are:

@pmonks pmonks changed the title CVE-2018-7489 affecting SJC Numerous Jackson CVEs affecting SJC Apr 16, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant