adobe / adobe/aem-testing-clients
jackson-databind and core CVEs
- Dominant language
- Java
- Stars
- 57
- Forks
- 39
- PR merge metrics
- No merged PRs in 30d
Description
jackson-core 2.13.0 and jackson-databind 2.13.2.1 dependencies return High security vulnerabilities.
- [https://www.mend.io/vulnerability-database/CVE-2022-42003](https://www.mend.io/vulnerability-database/CVE-2022-42003)
- [https://www.mend.io/vulnerability-database/CVE-2022-42004](https://www.mend.io/vulnerability-database/CVE-2022-42004)
Any plans to implement recommendation to update to jackson-databind 2.13.4 or above?
Contributor guide
Research direction
Start by locating the dependency declarations for jackson-core 2.13.0 and jackson-databind 2.13.2.1. Update them in line with the issue's recommendation, then verify that the reported CVE-2022-42003 and CVE-2022-42004 vulnerabilities are no longer reported.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100