Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.12.14, 1.13.8
-
None
-
CVE-2021-20190
Description
Current Situation
- Currently JobScheduler components use jackson databind version 2.9.10.5
- a vulnerability affect this version,
Desired Behavior
- Due to a vulnerability Issue of older jackson databind releases the JobScheduler components should use the current version 2.9.10.7 that fixes the issues.