Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-9585

Update Jackson DataBind

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • Starter 11
    • Starter 12
    • Starter
    • None

    Description

      The current version of Jackson DataBind packaged in Sling Starter 11 has a number of known vulnerabilities and should be updated. This includes critical vulnerabilities such as:

      CVE-2019-17267
      CVE-2019-17531
      CVE-2019-14540
      CVE-2019-16335

      The recommendation is to upgrade to 2.9.10.5.

      Attachments

        Activity

          People

            dklco Dan Klco
            dklco Dan Klco
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: