Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgraded jackson-databind version from 2.9.9 to 2.9.9.1 - CVE-2019-12814 - CWE-200; CVE-2019-12384 - CWE-502 #2658

Merged

Conversation

lorthirk
Copy link

This PR bumps jackson-databind to 2.9.9.1 due to CVE-2019-12384 and CVE-2019-12814

Signed-off-by: Claudio Mezzasalma <claudio.mezzasalma@eurotech.com>
@lorthirk lorthirk added the CQ pending This PR needs a CQ to be approved from Eclipse before merging. label Jul 15, 2019
@lorthirk lorthirk requested a review from Coduz July 15, 2019 14:26
@lorthirk
Copy link
Author

CQ request

@lorthirk
Copy link
Author

CQ Approved!

@lorthirk lorthirk removed the CQ pending This PR needs a CQ to be approved from Eclipse before merging. label Jul 15, 2019
@lorthirk lorthirk changed the title Bump jackson-databind to 2.9.9.1 Upgraded jackson-databind version from 2.9.9 to 2.9.9.1 - CVE-2019-12814 - CWE-200; CVE-2019-12384 - CWE-502 Jul 15, 2019
@Coduz Coduz merged commit c277c49 into eclipse-kapua:develop Jul 16, 2019
@lorthirk lorthirk deleted the change-bumpJacksonDatabind_2.9.9.1 branch July 17, 2019 08:19
@Coduz Coduz added CQ approved The PR has passed CQ approvation Security This issue/PR has some security critical aspect and should be issued as soon as possible labels Sep 30, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CQ approved The PR has passed CQ approvation Security This issue/PR has some security critical aspect and should be issued as soon as possible
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants