Uploaded image for project: 'RAML Module Builder'
  1. RAML Module Builder
  2. RMB-907

jackson-databind 2.13.2.1, Vert.x 4.2.6, log4j 2.17.2 (CVE-2020-36518)

    XMLWordPrintable

Details

    • CP: sprint 136, CP: sprint 137
    • 1
    • Core: Platform
    • TBD

    Description

      Update jackson-databind from 2.13.1 to 2.13.2.1 fixing https://nvd.nist.gov/vuln/detail/CVE-2020-36518

      Update Vert.x from 4.2.5 to 4.2.6.

      Update log4j from 2.17.1 to 2.17.2.

      Additional information

      Regarding jackson-databind upgrade from 2.13.1 to 2.13.2.1:

      BasicDeserializerFactory automatically returns the UntypedObjectDeserializer class for java type Object and Serializable:
      https://github.com/FasterXML/jackson-databind/blob/jackson-databind-2.13.2.1/src/main/java/com/fasterxml/jackson/databind/deser/BasicDeserializerFactory.java#-L2058-L2082

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                julianladisch Julian Ladisch
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases