Commit 0b8c86b
Upgrade jackson-bom to 2.21.1 to fix GHSA-72hv-8253-57qq (#1334)
*Issue #, if available:*
GHSA-72hv-8253-57qq
*Description of changes:*
Fixes jackson-core Number Length Constraint Bypass in Async Parser DoS
vulnerability (CVE in versions >= 2.0.0, <= 2.18.5).
By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>1 parent b58e829 commit 0b8c86b
3 files changed
Lines changed: 4 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
| 11 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
| 23 | + | |
22 | 24 | | |
23 | 25 | | |
24 | 26 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| |||
0 commit comments