adobe / adobe/aem-testing-clients

jackson-databind and core CVEs

Open
#88 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
57
Forks
39
PR merge metrics
No merged PRs in 30d

Description

jackson-core 2.13.0 and jackson-databind 2.13.2.1 dependencies return High security vulnerabilities.

- [https://www.mend.io/vulnerability-database/CVE-2022-42003](https://www.mend.io/vulnerability-database/CVE-2022-42003)
- [https://www.mend.io/vulnerability-database/CVE-2022-42004](https://www.mend.io/vulnerability-database/CVE-2022-42004)

Any plans to implement recommendation to update to jackson-databind 2.13.4 or above?

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declarations for jackson-core 2.13.0 and jackson-databind 2.13.2.1. Update them in line with the issue's recommendation, then verify that the reported CVE-2022-42003 and CVE-2022-42004 vulnerabilities are no longer reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.