Details
-
Fix
-
Status: Released (View Workflow)
-
Blocker
-
Resolution: Fixed
-
None
-
None
-
CVE-2018-7489
Description
Current Situation
- Currently JOC Cockpit and JobScheduler use Jackson version 2.4.3.
- A vulnerability affects this version, see https://www.cvedetails.com/cve/CVE-2018-7489/
Desired Behavior
- Due to a vulnerability Issue of older Jackson releases the JOC Cockpit as well as the JobScheduler should use the current version 2.9.7 that fixes the issues.
Maintainer Notes
Release 1.11 that includes Jackson version 2.4.3 is at its end of life. Therefore no maintenance release is provided.
Users of release 1.11 should therefore upgrade to release 1.12.