From d353c3bf4f03fbea95050bcc9544ca354c87db7e Mon Sep 17 00:00:00 2001 From: "Joseph (Ting-Chou) Lin" Date: Fri, 1 Apr 2022 10:51:31 -0700 Subject: [PATCH] CVE-2020-36518: Bump jackson-databind to 2.13.2.2 This resolves #4145, the jackson-databind CVE. A similar patch is also made in swagger-parser (swagger-parser#1690) --- modules/swagger-project-jakarta/pom.xml | 7 ++++++- pom.xml | 7 ++++++- 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/modules/swagger-project-jakarta/pom.xml b/modules/swagger-project-jakarta/pom.xml index f75eb7e964..04a9521b6e 100644 --- a/modules/swagger-project-jakarta/pom.xml +++ b/modules/swagger-project-jakarta/pom.xml @@ -494,7 +494,7 @@ com.fasterxml.jackson.core jackson-databind - ${jackson-version} + ${jackson-databind-version} jakarta.activation @@ -576,6 +576,11 @@ 3.0.1 4.13.1 2.13.2 + + 2.13.2.2 1.2.9 4.8.138 31.0.1-jre diff --git a/pom.xml b/pom.xml index 0636699f1d..8f331ec93b 100644 --- a/pom.xml +++ b/pom.xml @@ -568,7 +568,7 @@ com.fasterxml.jackson.core jackson-databind - ${jackson-version} + ${jackson-databind-version} com.fasterxml.jackson.core @@ -656,6 +656,11 @@ 2.26 4.13.1 2.13.2 + + 2.13.2.2 1.2.9 4.8.138 31.0.1-jre