IBM / ibm-cos-sdk-java

ibm-cos-sdk-java

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

PRISMA-2023-0067: jackson-core package versions before 2.15.0 are vulnerable to Denial of Service (DoS)

tcherel opened this issue · comments

See FasterXML/jackson-core#827

Can we get a rough estimate as when this upgrade might be done/available?

Thanks.

Thanks for reporting the issue. I will work with our team and will update you with the rough estimate at the earliest. Thanks

@tcherel We looked in the the vulnerability details that you shared, and found that the mentioned vulnerable function is not used at all in this java-sdk. So we will upgrade this dependency version and will include it the next release.

Thanks @avinash1IBM
Good to hear that it is not vulnerable but good to hear that you will upgrade anyway (some of our customers are pushing back as long as vulnerability is there).
Do you have a rough ETA for the next release?

@tcherel a new version 2.13.1 of java is released which takes care of this vulnerability. So please close this issue.

Thanks @avinash1IBM
Closing.