Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability issue with org.codehaus.jackson:jackson-mapper-asl #15

Open
iskitsas opened this issue Mar 30, 2021 · 0 comments
Open

Vulnerability issue with org.codehaus.jackson:jackson-mapper-asl #15

iskitsas opened this issue Mar 30, 2021 · 0 comments

Comments

@iskitsas
Copy link
Contributor

Fix this vulnerability issue with version upgrade or move to the proposed artifact.

CVE-2019-10172
high severity
Vulnerable versions: <= 1.9.13

Patched version: No fix
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar to CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

Note: this artifact has been moved
com.fasterxml.jackson.core » jackson-databind

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant