Upgrade jackson-databind to 2.13.4.2 and other jackson deps to 2.13.4 (#4550)

Signed-off-by: Lucas Saldanha <lucascrsaldanha@gmail.com>
pull/4557/head
Lucas Saldanha 2 years ago committed by GitHub
parent 95bc9bd7bc
commit 5c5d643f45
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
  1. 1
      CHANGELOG.md
  2. 4
      gradle/versions.gradle

@ -4,6 +4,7 @@
- Version 22.10.0 will require Java 17 to build and run.
### Additions and Improvements
- Updated jackson-databind library to version 2.13.4.2 addressing [CVE-2022-42003](https://nvd.nist.gov/vuln/detail/CVE-2022-42003)
## 22.10.0-RC2

@ -21,8 +21,8 @@ dependencyManagement {
entry 'antlr4-runtime'
}
dependencySet(group:'com.fasterxml.jackson.core', version:'2.13.3') {
entry 'jackson-databind'
dependency 'com.fasterxml.jackson.core:jackson-databind:2.13.4.2'
dependencySet(group:'com.fasterxml.jackson.core', version:'2.13.4') {
entry 'jackson-datatype'
entry 'jackson-datatype-jdk8'
}

Loading…
Cancel
Save