Skip to content

Jackson Databind Vulnerability in Plugins - S3 Repository and Discovery EC2 #27359

@davehagler

Description

@davehagler

Upgrade Jackson Databind dependency to fix deserialization vulnerability CVE-2017-7525. The plugins are currently using com.fasterxml.jackson.core:jackson-databind:2.5.3. It needs to be upgraded to one of these versions 2.6.7.1, 2.7.9.1, 2.8.9, 2.9.0

Reference FasterXML/jackson-databind#1723

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions