Skip to content

Security: Bump jackson-databind to 2.13.2.2#414

Merged
poovamraj merged 2 commits intomasterfrom
security/bump-jackson-databind
Mar 30, 2022
Merged

Security: Bump jackson-databind to 2.13.2.2#414
poovamraj merged 2 commits intomasterfrom
security/bump-jackson-databind

Conversation

@evansims
Copy link
Copy Markdown
Contributor

@evansims evansims commented Mar 26, 2022

This PR bumps the jackson-databind dependency to 2.13.2.1 to address CVE-2020-36518 in that library


Re: https://togithub.com/FasterXML/jackson-databind/issues/3428
Build is currently failing due to an upstream issue; holding until resolved.


A package fix was released as 2.13.2.2. I've updated the PR and marked as ready for review.

@evansims evansims added CH: Security dependencies One or more dependencies are being bumped labels Mar 26, 2022
@evansims evansims changed the title Security: Bump jackson-databind to 2.13.2.1 Security: Bump jackson-databind to 2.13.2.2 Mar 29, 2022
@evansims evansims added the review:tiny Tiny review label Mar 29, 2022
@evansims evansims marked this pull request as ready for review March 29, 2022 18:11
@evansims evansims requested a review from a team as a code owner March 29, 2022 18:11
@poovamraj poovamraj added this to the v1-Next milestone Mar 30, 2022
@poovamraj poovamraj merged commit 54e3b43 into master Mar 30, 2022
@poovamraj
Copy link
Copy Markdown
Contributor

We need to bump java-jwt as well. I will create a PR for it once it is released.

@poovamraj poovamraj modified the milestones: v1-Next, 1.40.1 Mar 30, 2022
@poovamraj poovamraj mentioned this pull request Mar 30, 2022
@evansims evansims deleted the security/bump-jackson-databind branch July 5, 2022 20:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants