square / square-java-sdk

Java client library for the Square API

Home Page:https://developer.squareup.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

There is a vulnerability in jackson-databind 2.9.10.53 ,upgrade recommended

QiAnXinCodeSafe opened this issue · comments

<jackson.databind.version>2.9.10.5</jackson.databind.version>

CVE-2021-20190 CVE-2020-24616 CVE-2020-36179 CVE-2020-36181 CVE-2020-36183

Recommended upgrade version:
2.9.10.8

The latest SDK has an updated version of jackson-databind.