Description
com.fasterxml.jackson.core:jackson-databind:2.9.8
This was picked up by SourceClear and Snyk as a downstream dependendency vulnerability. I'm not sure where jackson is used in your code, but it appears to be a "high" vulnerability.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12086
https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736
Solution: Upgrade to 2.9.9
Environment
- Version of this library used:
com.auth0:auth0:1.13.2