Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-42004 - Update jackson version #588

Closed
stummb opened this issue Sep 15, 2023 · 3 comments
Closed

CVE-2022-42004 - Update jackson version #588

stummb opened this issue Sep 15, 2023 · 3 comments
Assignees

Comments

@stummb
Copy link
Contributor

stummb commented Sep 15, 2023

cloudevents-jackson-json still uses jackson 2.13.3, which is vulnerable: https://nvd.nist.gov/vuln/detail/CVE-2022-42004

I can prepare an PR. Which version would be appropriate? Current versions are 2.13.5, 2.14.3, 2.15.2.
#575 and #577 bumped jackson-dataformat-yaml to 2.15.2 in cloudevents-sql, I guess that is the most reasonable choice.

stummb added a commit to stummb/sdk-java that referenced this issue Sep 18, 2023
stummb added a commit to stummb/sdk-java that referenced this issue Sep 18, 2023
Signed-off-by: Boris Stumm <bs@boris-stumm.de>
pierDipi pushed a commit that referenced this issue Oct 2, 2023
Signed-off-by: Boris Stumm <bs@boris-stumm.de>
@pierDipi
Copy link
Member

pierDipi commented Oct 2, 2023

PR merged eaef3be

@duglin
Copy link
Contributor

duglin commented Feb 1, 2024

@pierDipi has a new release been made with this patch?

@pierDipi
Copy link
Member

pierDipi commented Feb 1, 2024

I don't think so, this requires a major release and we're batching changes for a 3.0, however, users can change dependencies versions in their own projects

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants