File tree Expand file tree Collapse file tree 2 files changed +12
-2
lines changed
modules/swagger-project-jakarta Expand file tree Collapse file tree 2 files changed +12
-2
lines changed Original file line number Diff line number Diff line change 494494 <dependency >
495495 <groupId >com.fasterxml.jackson.core</groupId >
496496 <artifactId >jackson-databind</artifactId >
497- <version >${jackson-version} </version >
497+ <version >${jackson-databind- version} </version >
498498 <exclusions >
499499 <exclusion >
500500 <groupId >jakarta.activation</groupId >
576576 <jersey2-version >3.0.1</jersey2-version >
577577 <junit-version >4.13.1</junit-version >
578578 <jackson-version >2.13.2</jackson-version >
579+ <!--
580+ 2.13.2 is still affected by CVE-2020-36518.
581+ This version pin for jackson-databind can be removed when bumping jackson to 2.14
582+ -->
583+ <jackson-databind-version >2.13.2.2</jackson-databind-version >
579584 <logback-version >1.2.9</logback-version >
580585 <classgraph-version >4.8.138</classgraph-version >
581586 <guava-version >31.0.1-jre</guava-version >
Original file line number Diff line number Diff line change 568568 <dependency >
569569 <groupId >com.fasterxml.jackson.core</groupId >
570570 <artifactId >jackson-databind</artifactId >
571- <version >${jackson-version} </version >
571+ <version >${jackson-databind- version} </version >
572572 </dependency >
573573 <dependency >
574574 <groupId >com.fasterxml.jackson.core</groupId >
656656 <jersey2-version >2.26</jersey2-version >
657657 <junit-version >4.13.1</junit-version >
658658 <jackson-version >2.13.2</jackson-version >
659+ <!--
660+ jackson-databind 2.13.2 is still affected by CVE-2020-36518.
661+ This version pin for jackson-databind can be removed when bumping jackson to 2.14
662+ -->
663+ <jackson-databind-version >2.13.2.2</jackson-databind-version >
659664 <logback-version >1.2.9</logback-version >
660665 <classgraph-version >4.8.138</classgraph-version >
661666 <guava-version >31.0.1-jre</guava-version >
You can’t perform that action at this time.
0 commit comments