Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
1.12, 1.13
-
None
-
CVE-2018-10237
Description
Current Situation
- Currently JOC Cockpit and JobScheduler Master/Agent use Guava version 21.0
- A vulnerability affects this version, see https://nvd.nist.gov/vuln/detail/CVE-2018-10237 and https://www.cvedetails.com/cve/CVE-2018-10237/ https://nvd.nist.gov/vuln/detail/CVE-2018-10237
Desired Behavior
- Due to a vulnerability Issue of older Jackson releases the JOC Cockpit as well as the JobScheduler Master/Agent should use the current version 24.1.1 that fixes the issues.