Uploaded image for project: 'folio-spring-base'
  1. folio-spring-base
  2. FOLSPRINGB-78

RMB 35.0.1, commons-text 1.10.0 fixing vulns

    XMLWordPrintable

Details

    • Spitfire
    • Nolana (R3 2022)
    • Related dependency upgrade

    Description

      Upgrade jackson-databind from 2.13.3 to 2.13.4.2 fixing Denial of Service (DoS) vulnerabilities:
      https://nvd.nist.gov/vuln/detail/CVE-2022-42003
      https://nvd.nist.gov/vuln/detail/CVE-2022-42004

      Upgrade commons-text from 1.9 to 1.10.0 fixing Arbitrary Code Execution
      https://nvd.nist.gov/vuln/detail/CVE-2022-42889

      Upgrade RMB from 33.2.4 to 35.0.1.
      Note that org.folio:cql2pgjson is a component of RMB:
      https://github.com/folio-org/raml-module-builder/tree/v35.0.1

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                Unassigned Unassigned
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases