Skip to content

Jackson Dependency has vulnerable version #158

@yhtMinceraft1010X

Description

@yhtMinceraft1010X

The dependencies are shown below:

implementation group: 'com.fasterxml.jackson.core', name: 'jackson-databind', version: '2.7.0'
implementation group: 'com.fasterxml.jackson.datatype', name: 'jackson-datatype-jsr310', version: '2.7.4'

The corresponding report regarding the dependencies is given in the below file:
AB3 Dependency-Check Report.pdf

It is recommended to upgrade to at least 2.9.8. However, an issue regarding relative path serialization is causing some test cases to fail due to the output paths being absolute.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions