Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.13.9
-
None
-
CVE-2020-36186
Description
Current Situation
- Currently JOC Cockpit Web Services use jackson databind version 2.9.10.7
- a vulnerability affect this version,
Desired Behavior
- Due to a vulnerability Issue of older jackson databind releases JOC Cockpit Web Services should use the current version 2.9.10.8 that fixes the issues.