There is a CVE out on Jackson versions before 2.10.0... We need to upgrade to 2.10.0 to get a fix.
see CVE-2019-16942
- is duplicated by
-
GEODE-7264 Jackson-databind vulnerabilities
-
- Closed
-
- relates to
-
GEODE-7306 Upgrade Jackson-databind from 2.9.8 to 2.10.0
-
- Closed
-
-
GEODE-7264 Jackson-databind vulnerabilities
-
- Closed
-
- links to