Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remote code execution vulnerability in jackson-databind before 2.9.9.2 (CVE-2019-14379) #3287

Closed
goranoberg opened this issue Sep 10, 2019 · 1 comment

Comments

@goranoberg
Copy link

The latest release https://github.com/swagger-api/swagger-core/releases/tag/v2.0.9 is using jackson-databind 2.9.9 which has a known vulnerability with a CVSSv3 score of 9.8/10 (CRITICAL).

This tends to blocks the use of this dependency in most security aware CI/CD-systems.

https://nvd.nist.gov/vuln/detail/CVE-2019-14379

frantuma added a commit that referenced this issue Sep 27, 2019
frantuma added a commit that referenced this issue Sep 27, 2019
frantuma added a commit that referenced this issue Sep 27, 2019
frantuma added a commit that referenced this issue Sep 27, 2019
@frantuma
Copy link
Member

jackson updated in #3307 and #3308

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants