Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
None
-
None
Description
Current Situation
Currently JOC Cockpit and JobScheduler use Jackson Databind version 2.9.10.
Vulnerabilities affect this version, see CVE-2019-17531, CVE-2019-16943 and CVE-2019-16942
Desired Behavior
Due to a vulnerability Issue of older Jackson releases the JOC Cockpit as well as the JobScheduler should use the current version 2.9.10.1 that fixes the issues.