-
Notifications
You must be signed in to change notification settings - Fork 161
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Updated jackson-databind version to 2.9.9.2 #301
Conversation
Updated jackson-databind version to 2.9.9.2 which contains fix for: - [CVE-2019-14379](FasterXML/jackson-databind#2387) - [CVE-2019-14361 / CVE-2019-14439](FasterXML/jackson-databind#2389)
In addition a new release after merge would be great 🙂 |
Can I support in any way? |
@mibo Is there evidence to suggest that either of these CVEs is likely to impact the Connectors usage of Jackson? The shaded version of Jackson in Connectors is only used to parse I can merge this PR, but I'm hesitant to do a Connectors release for every Jackson version that gets released, as this happens pretty frequently. Is there something else that is driving the urgency of this? Note that this project is in maintenance mode. While we will continue to address security-related issues, releases will generally be less frequent than they have been in the past. |
I can completely understand your point. Our issue is that we do regular security scans and update vulnerable versions (like Nevertheless we would be happy about a new release 🙂 |
I was afraid that was the case :-).
I concur. I'll merge the change, but I'd like to wait a while for the release to make sure we don't get another Jackson version bump in the near future (as often happens, it seems). I recommend looking into the Java CfEnv project mentioned about as a replacement for Connectors. It is a much smaller library, with far fewer dependencies (and no shaded Jackson libs), that delegates most of the work to Spring Boot auto-configuration libs. |
Sorry for that 🙃
Thanks for confirmation.
Thanks and I really appreciate this....
...and this is fine for me and as written we also look for better solution in the future.
We also recommended this to our colleagues. However for some it seems to be not that easy. |
Updated jackson-databind version to 2.9.9.2 which contains fix for: