Skip to content

Conversation

@wkurniawan07
Copy link
Contributor

@wkurniawan07 wkurniawan07 commented Jan 23, 2023

Fixes

Updates jackson-related libraries to 2.13.4 or 2.13.4.2 (latest version for 2.13). This mitigates CVE-2022-42003 and CVE-2022-42002.

@rogierslag
Copy link

We'd also be interested in this release, as Jackson 2.13.3 has 3 open CVEs

Note that 2.13.4.2 is still vulnerable for the last one, best would be an update to 2.16.1

@tiwarishubham635
Copy link
Contributor

Hello! I am from twilio and I have looked at this PR. I created #745 that will be addressing this issue. Closing this PR here. Please create a new issue if further assistance is needed. Thanks!

@wkurniawan07 wkurniawan07 deleted the jackson-version branch January 18, 2024 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants