Details
-
Feature
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.13.18
-
None
-
CVE-2022-42003
Description
Current Situation
JS1 uses jackson-databind 2.13.4.1.
A vulnerability affects this version, seeĀ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42003.
We rate this vulnerability as LOW as nested arrays are not supported.
Desired Behavior
The JS1 and JS7 JOC Cockpit should use jackson-databind 2.14.2 which solves the issue.