Skip to content

Jackson upgrade for vulnerability issue #405

Open
junaidwarsivd wants to merge 3 commits intoj-easy:masterfrom
junaidwarsivd:jackson-upgrade
Open

Jackson upgrade for vulnerability issue #405
junaidwarsivd wants to merge 3 commits intoj-easy:masterfrom
junaidwarsivd:jackson-upgrade

Conversation

@junaidwarsivd
Copy link
Copy Markdown

current version of Jackson being used in release easyrules release (4.1.0) has a vulnerability issues
Deserialization of Untrusted Data (High) - CWE-502
XML External Entity (XXE) Injection (High) - CWE-611 - CVE-2020-25649
Denial of Service (DoS) - CWE-400
this PR is for the upgrade for jackson databind dependency which covers the issues mentioned above

@SebaMutuku
Copy link
Copy Markdown

@fmbenhassine do you have sometime to look at this and maybe merge it?

@fmbenhassine
Copy link
Copy Markdown
Member

Yes. I am planning to do a release soon. I will make sure to include updated dependencies.

@melloware
Copy link
Copy Markdown

Any update on this?

Comment thread pom.xml
<system-lambda.version>1.1.1</system-lambda.version>
<slf4j.version>1.7.30</slf4j.version>
<jackson.version>2.11.3</jackson.version>
<jackson.version>2.14.0</jackson.version>
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<jackson.version>2.14.0</jackson.version>
<jackson.version>2.15.2</jackson.version>

@pdob-git
Copy link
Copy Markdown

@junaidwarsivd Thank you very much.
I have updated my project from your fork 😄 👍

@Joe2k
Copy link
Copy Markdown

Joe2k commented Feb 8, 2024

@fmbenhassine Any update on the release? Also possible to look into this issue where exception is happening in JDK 21. Thanks a lot!

@xiangdyzz
Copy link
Copy Markdown

Why not merge?

@xiangdyzz
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

8 participants