Uploaded image for project: 'TomEE'
  1. TomEE
  2. TOMEE-2655

Depends on vulnerable Jackson Version

    XMLWordPrintableJSON

Details

    Description

      TomEE 7.1.1 depends on jackson-databind 2.9.6

      TomEE 8.0.0-M3 ships an even older version 2.9.4.

      All jackson versions up to 2.9.9.1 are vulnerable. Vulnerabilities in this component are hard to mitigate, because it is likly that it parses network data.

      This issue currently blocks my company from using TomEE out of the box.

      Attachments

        Activity

          People

            rzo1 Richard Zowalla
            robert.schaft Robert Schaft
            Votes:
            1 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: