CVE-2019-14439: bump jackson-databind to 2.9.9.3 #2688
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
PR #2671 bumps the
jackson-databind
version to 2.9.9. However, this version is susceptible to CVE-2019-14439 (original issue: FasterXML/jackson-databind#2389). While the vulnerability might not be directly exploitable from Akka HTTP, it might still pose a problem for projects pulling it in as a transitive dependency.This PR bumps
jackson-databind
further, to its latest stable version, 2.9.9.3.FYI, there are three more CVE's of this kind present in all versions of
jackson-databind
, including this one - they will be fixed in the forthcoming 2.10.0 release:FasterXML/jackson-databind#2410
FasterXML/jackson-databind#2420
FasterXML/jackson-databind#2421