Skip to content

Upgrade Jackson to 2.13.2.2#67

Merged
gabor-boros merged 1 commit intorethinkdb:masterfrom
Scarsz:patch-1
May 19, 2022
Merged

Upgrade Jackson to 2.13.2.2#67
gabor-boros merged 1 commit intorethinkdb:masterfrom
Scarsz:patch-1

Conversation

@Scarsz
Copy link
Copy Markdown
Contributor

@Scarsz Scarsz commented May 17, 2022

Reason for the change

Jackson implemented native support for record classes, making serialization trivial for data POJOs.

In addition, upgrading fixes vulnerabilities:
CVE-2020-25649 7.5 Improper Restriction of XML External Entity Reference vulnerability pending CVSS allocation
CVE-2021-20190 8.1 Deserialization of Untrusted Data vulnerability pending CVSS allocation
CVE-2020-10650 8.1 Deserialization of Untrusted Data vulnerability pending CVSS allocation
Cxced0c06c-935c 5.9 Uncontrolled Resource Consumption vulnerability pending CVSS allocation
CVE-2020-36518 7.5 Out-of-bounds Write vulnerability pending CVSS allocation

Checklist

Copy link
Copy Markdown
Member

@gabor-boros gabor-boros left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @Scarsz,

Thank you (again) for your contribution! This looks good to me, merging!

@gabor-boros gabor-boros merged commit 0d758ff into rethinkdb:master May 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants