Uploaded image for project: 'mod-source-record-manager'
  1. mod-source-record-manager
  2. MODSOURMAN-667

JsonNode JDK serialization DoS vulnerability

    XMLWordPrintable

Details

    • 0
    • Folijet
    • Lotus R1 2022
    • Not a bug

    Description

      mod-source-record-manager-server uses jackson-databind 2.10.* that is vulnerable to this Denial-of-Service vulnerability:

      Affected jackson-databind versions: < 2.12.6, 2.13.0

      mod-source-record-manager-server (all versions <= 3.2.7) currently uses unsupported jackson-databind 2.10.*.

      FOLIO modules use JsonNode in at least 36 files: https://github.com/search?q=org%3Afolio-org+jsonnode&type=code

      Task:
      Either

      • fix by removing or updating kafka-junit (see MODSOURMAN-636), or
      • investigate how mod-source-record-manager-server is affected by this vulnerability and explain why it is not affected.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                Unassigned Unassigned
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases