Skip to content

Commit d291df6

Browse files
authored
Bump version of Jackson libraries to 2.15.2
Previous versions of Jackson libraries included an old version of snakeyaml which was susceptible to CVE-2022-1471.
1 parent cd6b641 commit d291df6

File tree

2 files changed

+7
-5
lines changed

2 files changed

+7
-5
lines changed

driver-core/pom.xml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -164,6 +164,10 @@
164164
</exclusion>
165165
</exclusions>
166166
</dependency>
167+
<dependency>
168+
<groupId>com.fasterxml.jackson.core</groupId>
169+
<artifactId>jackson-core</artifactId>
170+
</dependency>
167171
<dependency>
168172
<groupId>com.fasterxml.jackson.core</groupId>
169173
<artifactId>jackson-databind</artifactId>

pom.xml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -61,9 +61,7 @@
6161
<snappy.version>1.1.2.6</snappy.version>
6262
<lz4.version>1.4.1</lz4.version>
6363
<hdr.version>2.1.10</hdr.version>
64-
<jackson.version>2.8.11</jackson.version>
65-
<!-- jackson-databind 2.7.x is the last to support java 6 -->
66-
<jackson-databind.version>2.7.9.7</jackson-databind.version>
64+
<jackson.version>2.15.2</jackson.version>
6765
<joda.version>2.9.9</joda.version>
6866
<jsr353-api.version>1.0</jsr353-api.version>
6967
<jsr353-ri.version>1.0.4</jsr353-ri.version>
@@ -202,7 +200,7 @@
202200
<dependency>
203201
<groupId>com.fasterxml.jackson.core</groupId>
204202
<artifactId>jackson-databind</artifactId>
205-
<version>${jackson-databind.version}</version>
203+
<version>${jackson.version}</version>
206204
</dependency>
207205

208206
<dependency>
@@ -560,7 +558,7 @@
560558
<additionalDependency>
561559
<groupId>com.fasterxml.jackson.core</groupId>
562560
<artifactId>jackson-databind</artifactId>
563-
<version>${jackson-databind.version}</version>
561+
<version>${jackson.version}</version>
564562
</additionalDependency>
565563
<additionalDependency>
566564
<groupId>joda-time</groupId>

0 commit comments

Comments
 (0)