Skip to content

Commit d353c3b

Browse files
lmr3796frantuma
authored andcommitted
CVE-2020-36518: Bump jackson-databind to 2.13.2.2
This resolves #4145, the jackson-databind CVE. A similar patch is also made in swagger-parser (swagger-parser#1690)
1 parent 0a16eb7 commit d353c3b

File tree

2 files changed

+12
-2
lines changed

2 files changed

+12
-2
lines changed

modules/swagger-project-jakarta/pom.xml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -494,7 +494,7 @@
494494
<dependency>
495495
<groupId>com.fasterxml.jackson.core</groupId>
496496
<artifactId>jackson-databind</artifactId>
497-
<version>${jackson-version}</version>
497+
<version>${jackson-databind-version}</version>
498498
<exclusions>
499499
<exclusion>
500500
<groupId>jakarta.activation</groupId>
@@ -576,6 +576,11 @@
576576
<jersey2-version>3.0.1</jersey2-version>
577577
<junit-version>4.13.1</junit-version>
578578
<jackson-version>2.13.2</jackson-version>
579+
<!--
580+
2.13.2 is still affected by CVE-2020-36518.
581+
This version pin for jackson-databind can be removed when bumping jackson to 2.14
582+
-->
583+
<jackson-databind-version>2.13.2.2</jackson-databind-version>
579584
<logback-version>1.2.9</logback-version>
580585
<classgraph-version>4.8.138</classgraph-version>
581586
<guava-version>31.0.1-jre</guava-version>

pom.xml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -568,7 +568,7 @@
568568
<dependency>
569569
<groupId>com.fasterxml.jackson.core</groupId>
570570
<artifactId>jackson-databind</artifactId>
571-
<version>${jackson-version}</version>
571+
<version>${jackson-databind-version}</version>
572572
</dependency>
573573
<dependency>
574574
<groupId>com.fasterxml.jackson.core</groupId>
@@ -656,6 +656,11 @@
656656
<jersey2-version>2.26</jersey2-version>
657657
<junit-version>4.13.1</junit-version>
658658
<jackson-version>2.13.2</jackson-version>
659+
<!--
660+
jackson-databind 2.13.2 is still affected by CVE-2020-36518.
661+
This version pin for jackson-databind can be removed when bumping jackson to 2.14
662+
-->
663+
<jackson-databind-version>2.13.2.2</jackson-databind-version>
659664
<logback-version>1.2.9</logback-version>
660665
<classgraph-version>4.8.138</classgraph-version>
661666
<guava-version>31.0.1-jre</guava-version>

0 commit comments

Comments
 (0)