Skip to content

Commit 60c9cbc

Browse files
authored
JAVA-3100: Update jackson-databind to 2.13.4.1 and (#1694)
jackson-jaxrs-json-provider to 2.13.4 to address recent CVEs Additional: - Remove unused maven property legacy-jackson.version
1 parent ec93ef9 commit 60c9cbc

File tree

2 files changed

+8
-3
lines changed

2 files changed

+8
-3
lines changed

core/revapi.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6950,6 +6950,12 @@
69506950
"old": "method <T> com.datastax.oss.driver.api.core.type.reflect.GenericType<com.datastax.oss.driver.api.core.data.CqlVector<T>> com.datastax.oss.driver.api.core.type.reflect.GenericType<T>::vectorOf(com.datastax.oss.driver.api.core.type.reflect.GenericType<T>)",
69516951
"new": "method <T extends java.lang.Number> com.datastax.oss.driver.api.core.type.reflect.GenericType<com.datastax.oss.driver.api.core.data.CqlVector<T>> com.datastax.oss.driver.api.core.type.reflect.GenericType<T>::vectorOf(com.datastax.oss.driver.api.core.type.reflect.GenericType<T>)",
69526952
"justification": "Refactorings in PR 1666"
6953+
},
6954+
{
6955+
"code": "java.method.returnTypeChangedCovariantly",
6956+
"old": "method java.lang.Throwable java.lang.Throwable::fillInStackTrace() @ com.fasterxml.jackson.databind.deser.UnresolvedForwardReference",
6957+
"new": "method com.fasterxml.jackson.databind.deser.UnresolvedForwardReference com.fasterxml.jackson.databind.deser.UnresolvedForwardReference::fillInStackTrace()",
6958+
"justification": "Upgrade jackson-databind to 2.13.4.1 to address CVEs, API change cause: https://github.com/FasterXML/jackson-databind/issues/3419"
69536959
}
69546960
]
69556961
}

pom.xml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -57,9 +57,8 @@
5757
<slf4j.version>1.7.26</slf4j.version>
5858
<reactive-streams.version>1.0.3</reactive-streams.version>
5959
<json.version>20230227</json.version>
60-
<jackson.version>2.13.2</jackson.version>
61-
<jackson-databind.version>2.13.2.2</jackson-databind.version>
62-
<legacy-jackson.version>1.9.12</legacy-jackson.version>
60+
<jackson.version>2.13.4</jackson.version>
61+
<jackson-databind.version>2.13.4.1</jackson-databind.version>
6362
<!-- optional dependencies -->
6463
<snappy.version>1.1.10.1</snappy.version>
6564
<lz4.version>1.7.1</lz4.version>

0 commit comments

Comments
 (0)