You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@camel.apache.org by co...@apache.org on 2020/12/09 13:55:36 UTC

[camel] branch camel-3.4.x updated: Updating Jackson to 2.10.5 + Jackson Databind to 2.10.5.1 to pick up CVE fixes

This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch camel-3.4.x
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/camel-3.4.x by this push:
     new 53df67c  Updating Jackson to 2.10.5 + Jackson Databind to 2.10.5.1 to pick up CVE fixes
53df67c is described below

commit 53df67c985d0b63503b345dd6131f1a1f6018c9e
Author: Colm O hEigeartaigh <co...@apache.org>
AuthorDate: Wed Dec 9 13:54:33 2020 +0000

    Updating Jackson to 2.10.5 + Jackson Databind to 2.10.5.1 to pick up CVE fixes
---
 camel-dependencies/pom.xml | 28 +++++++++++++++-------------
 parent/pom.xml             |  5 +++--
 2 files changed, 18 insertions(+), 15 deletions(-)

diff --git a/camel-dependencies/pom.xml b/camel-dependencies/pom.xml
index 3b0652c..7f2dd7b 100644
--- a/camel-dependencies/pom.xml
+++ b/camel-dependencies/pom.xml
@@ -17,7 +17,8 @@
     limitations under the License.
 
 -->
-<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
+<project xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd" xmlns="http://maven.apache.org/POM/4.0.0"
+    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
   <modelVersion>4.0.0</modelVersion>
   <parent>
     <groupId>org.apache</groupId>
@@ -85,18 +86,18 @@
     <c3p0-version>0.9.5.5</c3p0-version>
     <caffeine-version>2.8.4</caffeine-version>
     <californium-version>2.0.0</californium-version>
-    <camel.osgi.activator />
-    <camel.osgi.dynamic />
+    <camel.osgi.activator></camel.osgi.activator>
+    <camel.osgi.dynamic></camel.osgi.dynamic>
     <camel.osgi.exclude.dependencies>false</camel.osgi.exclude.dependencies>
     <camel.osgi.export>${camel.osgi.export.pkg};-noimport:=true;${camel.osgi.version}</camel.osgi.export>
     <camel.osgi.export.pkg>$${replace;{local-packages};;;\;}</camel.osgi.export.pkg>
     <camel.osgi.failok>false</camel.osgi.failok>
     <camel.osgi.import>${camel.osgi.import.pkg}</camel.osgi.import>
-    <camel.osgi.import.additional />
-    <camel.osgi.import.before.defaults />
+    <camel.osgi.import.additional></camel.osgi.import.additional>
+    <camel.osgi.import.before.defaults></camel.osgi.import.before.defaults>
     <camel.osgi.import.camel.version>version="[$(version;==;${camel.osgi.version.clean}),$(version;=+;${camel.osgi.version.clean}))"</camel.osgi.import.camel.version>
     <camel.osgi.import.default.version>[$(version;==;$(@)),$(version;+;$(@)))</camel.osgi.import.default.version>
-    <camel.osgi.import.defaults />
+    <camel.osgi.import.defaults></camel.osgi.import.defaults>
     <camel.osgi.import.pkg>org.apache.camel.*;${camel.osgi.import.camel.version},
             ${camel.osgi.import.before.defaults},
             ${camel.osgi.import.defaults},
@@ -105,11 +106,11 @@
     <camel.osgi.import.strict.version>version="[$(version;===;${camel.osgi.version.clean}),$(version;==+;${camel.osgi.version.clean}))"</camel.osgi.import.strict.version>
     <camel.osgi.manifest>${project.build.outputDirectory}/META-INF/MANIFEST.MF</camel.osgi.manifest>
     <camel.osgi.private.pkg>!*</camel.osgi.private.pkg>
-    <camel.osgi.provide.capability />
-    <camel.osgi.require.capability />
+    <camel.osgi.provide.capability></camel.osgi.provide.capability>
+    <camel.osgi.require.capability></camel.osgi.require.capability>
     <camel.osgi.symbolic.name>${project.groupId}.${project.artifactId}</camel.osgi.symbolic.name>
     <camel.osgi.version>version=${project.version}</camel.osgi.version>
-    <camel.surefire.fork.vmargs />
+    <camel.surefire.fork.vmargs></camel.surefire.fork.vmargs>
     <cassandra-driver-guava-version>19.0</cassandra-driver-guava-version>
     <cassandra-driver-version>3.7.2</cassandra-driver-version>
     <cassandra-unit-version>3.1.3.2</cassandra-unit-version>
@@ -156,9 +157,9 @@
     <cxf-version-range>[3.3,4.0)</cxf-version-range>
     <cxf-xjc-plugin-version>3.3.1</cxf-xjc-plugin-version>
     <cxf-xjc-utils-version>3.3.1</cxf-xjc-utils-version>
-    <cxf.codegen.jvmArgs />
+    <cxf.codegen.jvmArgs></cxf.codegen.jvmArgs>
     <cxf.codegenplugin.forkmode>once</cxf.codegenplugin.forkmode>
-    <cxf.xjc.jvmArgs />
+    <cxf.xjc.jvmArgs></cxf.xjc.jvmArgs>
     <debezium-mysql-connector-version>8.0.16</debezium-mysql-connector-version>
     <debezium-version>1.1.2.Final</debezium-version>
     <deltaspike-version>1.9.4</deltaspike-version>
@@ -288,7 +289,8 @@
     <jackrabbit-version>2.21.1</jackrabbit-version>
     <jackson-spark-version>2.10.4</jackson-spark-version>
     <jackson-version>1.9.12</jackson-version>
-    <jackson2-version>2.10.4</jackson2-version>
+    <jackson2-databind-version>2.10.5.1</jackson2-databind-version>
+    <jackson2-version>2.10.5</jackson2-version>
     <jain-sip-ri-bundle-version>1.2.154_2</jain-sip-ri-bundle-version>
     <jakarta-api-version>2.1.5</jakarta-api-version>
     <jakarta-jaxb-version>2.3.2</jakarta-jaxb-version>
@@ -503,7 +505,7 @@
     <scribe-version>1.3.7</scribe-version>
     <servicemix-specs-version>2.9.0</servicemix-specs-version>
     <servlet-version-range>[3,4)</servlet-version-range>
-    <shiro-version>1.5.3</shiro-version>
+    <shiro-version>1.7.0</shiro-version>
     <shrinkwrap-descriptors-version>2.0.0</shrinkwrap-descriptors-version>
     <shrinkwrap-resolver-version>3.1.3</shrinkwrap-resolver-version>
     <shrinkwrap-version>1.2.6</shrinkwrap-version>
diff --git a/parent/pom.xml b/parent/pom.xml
index 2f4933a..5fda3ba 100644
--- a/parent/pom.xml
+++ b/parent/pom.xml
@@ -267,7 +267,8 @@
         <ivy-version>2.5.0</ivy-version>
         <jackson-version>1.9.12</jackson-version>
         <jackson-spark-version>2.10.4</jackson-spark-version>
-        <jackson2-version>2.10.4</jackson2-version>
+        <jackson2-version>2.10.5</jackson2-version>
+        <jackson2-databind-version>2.10.5.1</jackson2-databind-version>
         <jackrabbit-version>2.21.1</jackrabbit-version>
         <jain-sip-ri-bundle-version>1.2.154_2</jain-sip-ri-bundle-version>
         <jasminb-jsonapi-version>0.10</jasminb-jsonapi-version>
@@ -2631,7 +2632,7 @@
             <dependency>
                 <groupId>com.fasterxml.jackson.core</groupId>
                 <artifactId>jackson-databind</artifactId>
-                <version>${jackson2-version}</version>
+                <version>${jackson2-databind-version}</version>
             </dependency>
             <dependency>
                 <groupId>com.fasterxml.jackson.dataformat</groupId>