You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tika.apache.org by "Tim Allison (Jira)" <ji...@apache.org> on 2022/10/03 18:19:00 UTC
[jira] [Created] (TIKA-3869) Update jackson-databind when available
Tim Allison created TIKA-3869:
---------------------------------
Summary: Update jackson-databind when available
Key: TIKA-3869
URL: https://issues.apache.org/jira/browse/TIKA-3869
Project: Tika
Issue Type: Task
Reporter: Tim Allison
No sooner had the 2.5.0 release vote passed than another cve from jackson-databind landed in ossindex. For details: https://github.com/FasterXML/jackson-databind/issues/3590 and https://nvd.nist.gov/vuln/detail/CVE-2022-42003
We should update jackson-databind when the next non-rc version is available.
I'll add this to the "ossindex-ignore" list so we can get a clean build for now.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)