Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-59379

Update jackson-databind to 2.9.9.3

    Details

    • Similar Issues:

      Description

      Update jackson-databind from 2.9.9 to 2.9.9.3

      This is to address four separate CVEs, two of which are critical:

      As java-client-api uses three separate jackson modules, I suggest addressing problem by using jackson-bom POM import (2.9.9.20190807) in dependencyManagement.

        Attachments

          Activity

          Hide
          msymons Mark Symons added a comment -
          Show
          msymons Mark Symons added a comment - Submitted pull request: https://github.com/jenkinsci/java-client-api/pull/427

            People

            • Assignee:
              khmarbaise Karl-Heinz Marbaise
              Reporter:
              msymons Mark Symons
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: