Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

chore: bump jackson-databind from 2.13.3 to 2.13.4.2#738

Closed
wkurniawan07 wants to merge 5 commits into
sendgrid:mainsendgrid/sendgrid-java:mainfrom
wkurniawan07:jackson-versionwkurniawan07/sendgrid-java:jackson-versionCopy head branch name to clipboard
Closed

chore: bump jackson-databind from 2.13.3 to 2.13.4.2#738
wkurniawan07 wants to merge 5 commits into
sendgrid:mainsendgrid/sendgrid-java:mainfrom
wkurniawan07:jackson-versionwkurniawan07/sendgrid-java:jackson-versionCopy head branch name to clipboard

Conversation

@wkurniawan07

@wkurniawan07 wkurniawan07 commented Jan 23, 2023

Copy link
Copy Markdown
Contributor

Fixes

Updates jackson-related libraries to 2.13.4 or 2.13.4.2 (latest version for 2.13). This mitigates CVE-2022-42003 and CVE-2022-42002.

@rogierslag

Copy link
Copy Markdown

We'd also be interested in this release, as Jackson 2.13.3 has 3 open CVEs

Note that 2.13.4.2 is still vulnerable for the last one, best would be an update to 2.16.1

@tiwarishubham635

Copy link
Copy Markdown
Contributor

Hello! I am from twilio and I have looked at this PR. I created #745 that will be addressing this issue. Closing this PR here. Please create a new issue if further assistance is needed. Thanks!

@wkurniawan07 wkurniawan07 deleted the jackson-version branch January 18, 2024 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.