Skip to content
This repository has been archived by the owner on Dec 16, 2021. It is now read-only.

update jackson-databind to 2.9.9.1 #166

Merged
merged 1 commit into from
Jul 23, 2019
Merged

update jackson-databind to 2.9.9.1 #166

merged 1 commit into from
Jul 23, 2019

Conversation

yuyang08
Copy link
Contributor

Update jackson-databind to 2.9.9.1 for the security alert.

https://github.com/pinterest/doctorkafka/network/alert/drkafka/pom.xml/com.fasterxml.jackson.core:jackson-databind/open

CVE-2019-12814 More information
moderate severity
Vulnerable versions: >= 2.0.0, < 2.9.9.1
Patched version: 2.9.9.1
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When 
Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON 
endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically 
crafted JSON message that allows them to read arbitrary local files on the server.

@yuyang08 yuyang08 merged commit ab795b4 into pinterest:master Jul 23, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant