Details
-
Bug
-
Status: Closed (View Workflow)
-
P2
-
Resolution: Done
-
None
-
CP: sprint 136, CP: sprint 137
-
1
-
Core: Platform
-
TBD
Description
Update jackson-databind from 2.13.1 to 2.13.2.1 fixing https://nvd.nist.gov/vuln/detail/CVE-2020-36518
Update Vert.x from 4.2.5 to 4.2.6.
Update log4j from 2.17.1 to 2.17.2.
Additional information
Regarding jackson-databind upgrade from 2.13.1 to 2.13.2.1:
BasicDeserializerFactory automatically returns the UntypedObjectDeserializer class for java type Object and Serializable:
https://github.com/FasterXML/jackson-databind/blob/jackson-databind-2.13.2.1/src/main/java/com/fasterxml/jackson/databind/deser/BasicDeserializerFactory.java#-L2058-L2082