Skip to content

Upgrade to jackson-databind 2.14.0 when available #1381

@rjrudin

Description

@rjrudin

This CVE - https://avd.aquasec.com/nvd/2022/cve-2022-42003/ - references an issue in < 2.14.0 jackson-databind . #1377 will get us onto 2.13.4 of jackson-databind, and 2.14.0 is not yet available - it's at rc2 as of today. Once 2.14.0 is available, we'll want to upgrade to it, along with 2.14.0 for all jackson dependencies.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions