haiku / haikudepotserver

Haiku Depot Server

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Update jackson-databind due to CVE-2018-19360 (and others)

kallisti5 opened this issue · comments

7 com.fasterxml.jackson.core:jackson-databind vulnerabilities found in haikudepotserver-parent/pom.xml on Jan 4

Remediation
Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.9.8 or later. For example:

com.fasterxml.jackson.core jackson-databind [2.9.8,)