Skip to content

Security: Bump jackson-databind to 2.13.2.2#566

Merged
poovamraj merged 2 commits intomasterfrom
security/bump-jackson-databind
Mar 30, 2022
Merged

Security: Bump jackson-databind to 2.13.2.2#566
poovamraj merged 2 commits intomasterfrom
security/bump-jackson-databind

Conversation

@evansims
Copy link
Copy Markdown
Contributor

@evansims evansims commented Mar 26, 2022

This PR bumps the jackson-databind dependency to 2.13.2.2 to address CVE-2020-36518 in that library


Re: https://togithub.com/FasterXML/jackson-databind/issues/3428
Build is currently failing due to an upstream issue; holding until resolved.

--

A package fix was released as 2.13.2.2. I've updated the PR and marked as ready for review.

@evansims evansims added CH: Security dependencies One or more dependencies are being bumped labels Mar 26, 2022
@evansims evansims changed the title Security: Bump jackson-databind to 2.13.2.1 Security: Bump jackson-databind to 2.13.2.2 Mar 29, 2022
@evansims evansims added the review:tiny Tiny review label Mar 29, 2022
@evansims evansims marked this pull request as ready for review March 29, 2022 18:11
@evansims evansims requested a review from a team as a code owner March 29, 2022 18:11
@poovamraj poovamraj added this to the v3-Next milestone Mar 30, 2022
@poovamraj poovamraj merged commit dd22f32 into master Mar 30, 2022
@poovamraj poovamraj modified the milestones: v3-Next, 3.19.1 Mar 30, 2022
@poovamraj poovamraj mentioned this pull request Mar 30, 2022
@evansims evansims deleted the security/bump-jackson-databind branch July 5, 2022 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants