FasterXML jackson-databind 代码问题漏洞(CVE-2022-42003)
Open
dependencies
good first issue
- Dominant language
- Java
- Stars
- 23.1k
- Forks
- 8.1k
- PR merge metrics
- No merged PRs in 30d
Description
最新sentinel-dashboard1.8.6
中jackson-databind 版本是jackson-databind-2.12.6.1.jar
有处理此漏洞的计划吗?
CVE编号
CVE-2022-42003
披露时间
2022-10-02
修复方案
建议受影响客户升级到2.14.0-rc2及以上安全版本,版本获取链接:
https://github.com/FasterXML/jackson-databind
Contributor guide
Research direction
The issue names Sentinel Dashboard 1.8.6, jackson-databind-2.12.6.1.jar, CVE-2022-42003, and the FasterXML advisory link. First locate where that dependency version is declared and check upgrade compatibility; done means the affected version is no longer used and the vulnerability is addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100