Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.13.3
-
None
-
CVE-2019-20330, CVE-2020-8840
Description
Current Situation
- Currently JOC Cockpit and JobScheduler use Jackson Databind version 2.9.10.1
- A vulnerability affects this version, see https://nvd.nist.gov/vuln/detail/CVE-2019-20330 and https://www.cvedetails.com/cve/CVE-2019-14540/ https://nvd.nist.gov/vuln/detail/CVE-2020-8840
Desired Behavior
- Due to a vulnerability Issue of older Jackson releases the JOC Cockpit as well as the JobScheduler should use the current version 2.9.10.3 that fixes the issues.