Skip to content

Critical CVE related to com.fasterxml.jackson.core:jackson-databind #15832

@louptony

Description

@louptony

Hello,

4 CVEs (CVE-2018-14718, CVE-2018-14719, CVE-2018-14720, CVE-2018-14721) are brought up with the com.fasterxml.jackson.core:jackson-databind version 2.9.5 inlcuded in spring-cloud-cloudfoundry-connector. The corrections were fixed in version 2.9.8. The fix will be added in version 2.0.5 of spring-cloud-connectors.

Can the version be updated in a quick upcoming bug fix?

Thank you

Metadata

Metadata

Assignees

No one assigned

    Labels

    status: invalidAn issue that we don't feel is valid

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions