Details
-
Fix
-
Status: Released (View Workflow)
-
Major
-
Resolution: Fixed
-
1.13.4
-
None
-
CVE-2020-14195, CVE-2020-14062, CVE-2020-14060, CVE-2020-14061
Description
Current Situation
- JOC Cockpit uses the 3rd party library jackson-databind version 2.9.10.4
- A number of vulnerabilities affect this Jackson Databind version, see https://nvd.nist.gov/vuln/detail/CVE-2020-14195 etc.
Desired Behavior
- Due to vulnerability Issues of older jackson-databind releases the JOC Cockpit should use the current version 2.9.10.5 that fixes the issues.