Uploaded image for project: 'JOC - JobScheduler Operations Center'
  1. JOC - JobScheduler Operations Center
  2. JOC-1532

Update jackson-databind to 2.14.2 due to 3rd-party vulnerability issue CVE-2022-42003

    XMLWordPrintable

Details

    • CVE-2022-42003

    Description

      Current Situation

      JS1 uses jackson-databind 2.13.4.1.
      A vulnerability affects this version, seeĀ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42003.
      We rate this vulnerability as LOW as nested arrays are not supported.

      Desired Behavior
      The JS1 and JS7 JOC Cockpit should use jackson-databind 2.14.2 which solves the issue.

      Attachments

        Activity

          People

            sp Santiago Aucejo Petzoldt
            sp Santiago Aucejo Petzoldt
            Ajay Kumbhkar Ajay Kumbhkar
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: