Skip to content

Commit 99ffe61

Browse files
authored
[Io7UetI2] Update jackson to 2.17.2 and aws-java-sdk-s3 to 1.12.770 to mitigate CWE-400 (#4180)
1 parent dc04d3b commit 99ffe61

File tree

9 files changed

+47
-45
lines changed

9 files changed

+47
-45
lines changed

LICENSES.txt

Lines changed: 15 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,10 @@ Apache-2.0
2020
audience-annotations-0.12.0.jar
2121
avro-1.9.2.jar
2222
awaitility-4.1.0.jar
23-
aws-java-sdk-core-1.12.646.jar
24-
aws-java-sdk-kms-1.12.646.jar
25-
aws-java-sdk-s3-1.12.646.jar
26-
byte-buddy-1.14.9.jar
23+
aws-java-sdk-core-1.12.770.jar
24+
aws-java-sdk-kms-1.12.770.jar
25+
aws-java-sdk-s3-1.12.770.jar
26+
byte-buddy-1.11.13.jar
2727
byte-buddy-agent-1.11.13.jar
2828
caffeine-3.0.3.jar
2929
cassandra-driver-core-3.10.0.jar
@@ -97,20 +97,21 @@ Apache-2.0
9797
jPowerShell-3.0.jar
9898
jProcesses-1.6.5.jar
9999
jackson-annotations-2.15.2.jar
100-
jackson-annotations-2.17.0.jar
100+
jackson-annotations-2.17.2.jar
101101
jackson-core-2.15.2.jar
102-
jackson-core-2.17.0.jar
102+
jackson-core-2.17.2.jar
103103
jackson-databind-2.15.2.jar
104-
jackson-databind-2.17.0.jar
105-
jackson-dataformat-cbor-2.17.0.jar
106-
jackson-dataformat-csv-2.17.0.jar
104+
jackson-databind-2.17.2.jar
105+
jackson-dataformat-cbor-2.17.2.jar
106+
jackson-dataformat-csv-2.17.2.jar
107107
jackson-datatype-jsr310-2.17.0.jar
108+
jackson-datatype-jsr310-2.17.2.jar
108109
jackson-jaxrs-base-2.15.2.jar
109-
jackson-jaxrs-base-2.17.0.jar
110+
jackson-jaxrs-base-2.17.2.jar
110111
jackson-jaxrs-json-provider-2.15.2.jar
111-
jackson-jaxrs-json-provider-2.17.0.jar
112+
jackson-jaxrs-json-provider-2.17.2.jar
112113
jackson-module-jaxb-annotations-2.15.2.jar
113-
jackson-module-jaxb-annotations-2.17.0.jar
114+
jackson-module-jaxb-annotations-2.17.2.jar
114115
jakarta.validation-api-2.0.2.jar
115116
jamm-0.3.3.jar
116117
javapoet-1.13.0.jar
@@ -132,11 +133,11 @@ Apache-2.0
132133
jetty-xml-9.4.53.v20231009.jar
133134
jffi-1.2.16-native.jar
134135
jffi-1.2.16.jar
135-
jmespath-java-1.12.646.jar
136+
jmespath-java-1.12.770.jar
136137
jna-5.9.0.jar
137138
jnr-constants-0.9.9.jar
138139
jnr-ffi-2.1.7.jar
139-
joda-time-2.8.1.jar
140+
joda-time-2.12.7.jar
140141
json-path-2.9.0.jar
141142
json-smart-2.5.0.jar
142143
jsonschema2pojo-core-1.0.2.jar

NOTICE.txt

Lines changed: 15 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -50,10 +50,10 @@ Apache-2.0
5050
audience-annotations-0.12.0.jar
5151
avro-1.9.2.jar
5252
awaitility-4.1.0.jar
53-
aws-java-sdk-core-1.12.646.jar
54-
aws-java-sdk-kms-1.12.646.jar
55-
aws-java-sdk-s3-1.12.646.jar
56-
byte-buddy-1.14.9.jar
53+
aws-java-sdk-core-1.12.770.jar
54+
aws-java-sdk-kms-1.12.770.jar
55+
aws-java-sdk-s3-1.12.770.jar
56+
byte-buddy-1.11.13.jar
5757
byte-buddy-agent-1.11.13.jar
5858
caffeine-3.0.3.jar
5959
cassandra-driver-core-3.10.0.jar
@@ -127,20 +127,21 @@ Apache-2.0
127127
jPowerShell-3.0.jar
128128
jProcesses-1.6.5.jar
129129
jackson-annotations-2.15.2.jar
130-
jackson-annotations-2.17.0.jar
130+
jackson-annotations-2.17.2.jar
131131
jackson-core-2.15.2.jar
132-
jackson-core-2.17.0.jar
132+
jackson-core-2.17.2.jar
133133
jackson-databind-2.15.2.jar
134-
jackson-databind-2.17.0.jar
135-
jackson-dataformat-cbor-2.17.0.jar
136-
jackson-dataformat-csv-2.17.0.jar
134+
jackson-databind-2.17.2.jar
135+
jackson-dataformat-cbor-2.17.2.jar
136+
jackson-dataformat-csv-2.17.2.jar
137137
jackson-datatype-jsr310-2.17.0.jar
138+
jackson-datatype-jsr310-2.17.2.jar
138139
jackson-jaxrs-base-2.15.2.jar
139-
jackson-jaxrs-base-2.17.0.jar
140+
jackson-jaxrs-base-2.17.2.jar
140141
jackson-jaxrs-json-provider-2.15.2.jar
141-
jackson-jaxrs-json-provider-2.17.0.jar
142+
jackson-jaxrs-json-provider-2.17.2.jar
142143
jackson-module-jaxb-annotations-2.15.2.jar
143-
jackson-module-jaxb-annotations-2.17.0.jar
144+
jackson-module-jaxb-annotations-2.17.2.jar
144145
jakarta.validation-api-2.0.2.jar
145146
jamm-0.3.3.jar
146147
javapoet-1.13.0.jar
@@ -162,11 +163,11 @@ Apache-2.0
162163
jetty-xml-9.4.53.v20231009.jar
163164
jffi-1.2.16-native.jar
164165
jffi-1.2.16.jar
165-
jmespath-java-1.12.646.jar
166+
jmespath-java-1.12.770.jar
166167
jna-5.9.0.jar
167168
jnr-constants-0.9.9.jar
168169
jnr-ffi-2.1.7.jar
169-
joda-time-2.8.1.jar
170+
joda-time-2.12.7.jar
170171
json-path-2.9.0.jar
171172
json-smart-2.5.0.jar
172173
jsonschema2pojo-core-1.0.2.jar

core-it/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ dependencies {
99
testImplementation project(':test-utils')
1010
testImplementation project(':core').sourceSets.test.output
1111

12-
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
12+
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
1313
testImplementation group: 'org.xmlunit', name: 'xmlunit-core', version: '2.9.1'
1414

1515
configurations.all {

core/build.gradle

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ dependencies {
6262

6363
testImplementation 'net.sourceforge.jexcelapi:jxl:2.6.12'
6464

65-
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
65+
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
6666

6767
testImplementation group: 'org.reflections', name: 'reflections', version: '0.9.12'
6868
testImplementation group: 'junit', name: 'junit', version: '4.13.1'
@@ -98,8 +98,8 @@ dependencies {
9898
testImplementation 'org.mock-server:mockserver-netty:5.15.0'
9999
testImplementation 'org.mock-server:mockserver-client-java:5.15.0'
100100

101-
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.646' , withoutJacksons
102-
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.646' , withoutJacksons
101+
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.770' , withoutJacksons
102+
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.770' , withoutJacksons
103103

104104
implementation group: 'com.opencsv', name: 'opencsv', version: '5.7.1'
105105
implementation group: 'commons-beanutils', name: 'commons-beanutils', version: '1.9.4'

extra-dependencies/aws/build.gradle

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,6 @@ jar {
2020
}
2121

2222
dependencies {
23-
implementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
24-
implementation group: 'com.amazonaws', name: 'aws-java-sdk-sts', version: '1.12.646'
23+
implementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
24+
implementation group: 'com.amazonaws', name: 'aws-java-sdk-sts', version: '1.12.770'
2525
}

extra-dependencies/nlp/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ def withoutJacksons = {
2626

2727
dependencies {
2828
implementation group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.646' , withoutJacksons
29-
implementation group: 'com.fasterxml.jackson.module', name: 'jackson-module-kotlin', version: '2.14.0', withoutJacksons
29+
implementation group: 'com.fasterxml.jackson.module', name: 'jackson-module-kotlin', version: '2.17.2', withoutJacksons
3030
implementation 'org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.6.0'
3131
}
3232

full-it/build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ dependencies {
1111
testImplementation project(':core').sourceSets.test.output
1212
testImplementation project(':full').sourceSets.test.output
1313

14-
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
14+
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
1515
testImplementation group: 'org.xmlunit', name: 'xmlunit-core', version: '2.9.1'
1616

1717
configurations.all {

full/build.gradle

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -88,8 +88,8 @@ dependencies {
8888

8989
testImplementation 'net.sourceforge.jexcelapi:jxl:2.6.12'
9090

91-
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
92-
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
91+
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
92+
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
9393

9494
testImplementation group: 'org.reflections', name: 'reflections', version: '0.9.12'
9595

@@ -125,17 +125,17 @@ dependencies {
125125

126126
compileOnly group: 'org.neo4j', name: 'neo4j', version: neo4jVersionEffective
127127

128-
compileOnly group: 'com.fasterxml.jackson.module', name: 'jackson-module-kotlin', version: '2.14.0', withoutJacksons
128+
compileOnly group: 'com.fasterxml.jackson.module', name: 'jackson-module-kotlin', version: '2.17.2', withoutJacksons
129129
compileOnly 'org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.6.0'
130130

131-
testImplementation group: 'com.fasterxml.jackson.module', name: 'jackson-module-kotlin', version: '2.14.0', withoutJacksons
131+
testImplementation group: 'com.fasterxml.jackson.module', name: 'jackson-module-kotlin', version: '2.17.2', withoutJacksons
132132
testImplementation 'org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.6.0'
133133

134134
testImplementation 'org.mock-server:mockserver-netty:5.15.0'
135135
testImplementation 'org.mock-server:mockserver-client-java:5.15.0'
136136

137-
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.646' , withoutJacksons
138-
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.646' , withoutJacksons
137+
compileOnly group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.770' , withoutJacksons
138+
testImplementation group: 'com.amazonaws', name: 'aws-java-sdk-comprehend', version: '1.12.770' , withoutJacksons
139139

140140
implementation group: 'com.opencsv', name: 'opencsv', version: '5.7.1'
141141
implementation group: 'commons-beanutils', name: 'commons-beanutils', version: '1.9.4'
@@ -154,7 +154,7 @@ dependencies {
154154
testImplementation group: 'org.hamcrest', name: 'hamcrest', version: '2.2'
155155
testImplementation group: 'org.hamcrest', name: 'hamcrest-library', version: '2.2'
156156

157-
testImplementation group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-csv', version: '2.14.0'
157+
testImplementation group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-csv', version: '2.17.2'
158158
testImplementation group: 'org.skyscreamer', name: 'jsonassert', version: '1.5.0'
159159
testImplementation group: 'org.assertj', name: 'assertj-core', version: '3.13.2'
160160

test-utils/build.gradle

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,9 @@ dependencies {
2929

3030
api group: 'org.neo4j.driver', name: 'neo4j-java-driver', version: '4.4.14'
3131
api group: 'org.jetbrains', name: 'annotations', version: "17.0.0"
32-
api group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.646'
32+
api group: 'com.amazonaws', name: 'aws-java-sdk-s3', version: '1.12.770'
3333

34-
api group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-csv', version: '2.14.0'
34+
api group: 'com.fasterxml.jackson.dataformat', name: 'jackson-dataformat-csv', version: '2.17.2'
3535

3636
// Test Containers
3737
api group: 'org.testcontainers', name: 'testcontainers', version: testContainersVersion

0 commit comments

Comments
 (0)