Vulnerabilities in Jackson Databind library -2.9.9.3 

Issue date: 15-01-2020
Affects versions: 13.4, 13.3, 12.5, 11.2

Issue ID

SECURITY-129

 

Affected Product Version(s)

13.4.0, 12.6.7, 11.2.16 (and previous minor and patch releases)


Severity 

Medium

Description

Jackson Databind reported vulnerabilities CVE-2019-14540 and CVE-2019-16335 in versions prior to jackson-databind 2.9.10.

The Jackson Databind dependency has been updated to version 2.10.1.

Instructions

Every customer is advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.