Skip to content

Commit ade41be

Browse files
lmr3796frantuma
authored andcommitted
CVE-2020-36518: Bump jackson-databind to 2.13.2.2
This resolves #1689 . There's a follow-up fix for the CVE in jackson-databind 2.12.6.1+/2.13.2.2+
1 parent b4ff52e commit ade41be

File tree

3 files changed

+8
-3
lines changed

3 files changed

+8
-3
lines changed

modules/swagger-parser-v2-converter/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@
5757
<dependency>
5858
<groupId>com.fasterxml.jackson.core</groupId>
5959
<artifactId>jackson-databind</artifactId>
60-
<version>${jackson-version}</version>
60+
<version>${jackson-databind-version}</version>
6161
<scope>provided</scope>
6262
</dependency>
6363
<dependency>

modules/swagger-parser-v3/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@
4747
<dependency>
4848
<groupId>com.fasterxml.jackson.core</groupId>
4949
<artifactId>jackson-databind</artifactId>
50-
<version>${jackson-version}</version>
50+
<version>${jackson-databind-version}</version>
5151
</dependency>
5252
<dependency>
5353
<groupId>com.fasterxml.jackson.dataformat</groupId>

pom.xml

+6-1
Original file line numberDiff line numberDiff line change
@@ -325,7 +325,7 @@
325325
<dependency>
326326
<groupId>com.fasterxml.jackson.core</groupId>
327327
<artifactId>jackson-databind</artifactId>
328-
<version>${jackson-version}</version>
328+
<version>${jackson-databind-version}</version>
329329
</dependency>
330330
<dependency>
331331
<groupId>com.fasterxml.jackson.core</groupId>
@@ -406,6 +406,11 @@
406406
<surefire-version>2.22.2</surefire-version>
407407
<commons-lang-version>3.2.1</commons-lang-version>
408408
<jackson-version>2.13.2</jackson-version>
409+
<!--
410+
2.13.2 is still affected by CVE-2020-36518.
411+
This version pin for jackson-databind can be removed when bumping jackson to 2.14
412+
-->
413+
<jackson-databind-version>2.13.2.2</jackson-databind-version>
409414
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
410415
<sonatypeOssDistMgmtSnapshotsUrl>https://oss.sonatype.org/content/repositories/snapshots/</sonatypeOssDistMgmtSnapshotsUrl>
411416
</properties>

0 commit comments

Comments
 (0)