You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@servicecomb.apache.org by GitBox <gi...@apache.org> on 2022/03/23 03:38:46 UTC

[GitHub] [servicecomb-java-chassis] kinkwok117 opened a new issue #2742: Jackson-databind 2.12.1有高分漏洞

kinkwok117 opened a new issue #2742:
URL: https://github.com/apache/servicecomb-java-chassis/issues/2742


   https://github.com/advisories/GHSA-57j2-w4cx-62h2


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@servicecomb.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [servicecomb-java-chassis] Shoothzj commented on issue #2742: Jackson-databind 2.12.1有高分漏洞

Posted by GitBox <gi...@apache.org>.
Shoothzj commented on issue #2742:
URL: https://github.com/apache/servicecomb-java-chassis/issues/2742#issuecomment-1076224171


   but jackson doesn't have aviable version yet


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@servicecomb.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [servicecomb-java-chassis] liubao68 commented on issue #2742: Jackson-databind 2.12.1有高分漏洞

Posted by GitBox <gi...@apache.org>.
liubao68 commented on issue #2742:
URL: https://github.com/apache/servicecomb-java-chassis/issues/2742#issuecomment-1080082710


   Jackson do not have a version to fix this yet. https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12
   
   Only jackson-databind got a patch version. We will fix this later when jackson released a version. And users can upgrade jackson-databind only before servicecomb release a patch. 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@servicecomb.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org