[Bug]: jackson-databind version upgrade to remediate security vulnerabilities #9528 Fix#9543
Closed
shanjare2002 wants to merge 3 commits intotestcontainers:mainfrom
Closed
[Bug]: jackson-databind version upgrade to remediate security vulnerabilities #9528 Fix#9543shanjare2002 wants to merge 3 commits intotestcontainers:mainfrom
shanjare2002 wants to merge 3 commits intotestcontainers:mainfrom
Conversation
Member
|
Hi, how moving to patch version is going to fix security vulnerabilities? Can you elaborate? |
Author
|
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This is critical vulnerability, and was patched in jackson 2.8.9 version and up. Jackson is only used in the core |
Author
|
Can this merge request be checked it has been 3 months. |
Member
|
Is this affecting from the test perspective? The plan is to update dependencies in the next months. Thanks for raising the PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I changed the Jackon version from 2.8.8 -> 2.8.9