-
Notifications
You must be signed in to change notification settings - Fork 280
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ELY-2352] UpRev Jackson to 2.13.3 #1721
Conversation
Hi @DanSalt,
You want to change this, so the first line says
Here's some useful resources |
Simplified PR using later 2.13.3 Jackson
Thanks @Ashpan -- that was really helpful :) Should be all modified and ready to go now. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
https://issues.redhat.com/browse/ELY-2352
Addresses CVE-2020-36518
FasterXML/jackson-databind#2816
GHSA-57j2-w4cx-62h2
This fix improves on the Dependabot PR (#1699) which incorrectly bumps the version for the whole of Jackson to 2.13.2.1, which caused an error (because 2.13.2.1 only applied to jackson-databind). This PR bumps to the later (2.13.3) version, which also satisfies the CVE.