You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tika.apache.org by "Tim Allison (Jira)" <ji...@apache.org> on 2022/10/03 18:19:00 UTC

[jira] [Created] (TIKA-3869) Update jackson-databind when available

Tim Allison created TIKA-3869:
---------------------------------

             Summary: Update jackson-databind when available
                 Key: TIKA-3869
                 URL: https://issues.apache.org/jira/browse/TIKA-3869
             Project: Tika
          Issue Type: Task
            Reporter: Tim Allison


No sooner had the 2.5.0 release vote passed than another cve from jackson-databind landed in ossindex.  For details: https://github.com/FasterXML/jackson-databind/issues/3590 and https://nvd.nist.gov/vuln/detail/CVE-2022-42003

We should update jackson-databind when the next non-rc version is available.

I'll add this to the "ossindex-ignore" list so we can get a clean build for now.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)