Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade com.fasterxml.jackson.core to version 2.15 #16044

Closed
wendycwong opened this issue Jan 30, 2024 Discussed in #15934 · 1 comment
Closed

Upgrade com.fasterxml.jackson.core to version 2.15 #16044

wendycwong opened this issue Jan 30, 2024 Discussed in #15934 · 1 comment

Comments

@wendycwong
Copy link
Contributor

Discussed in #15934

Originally posted by trpellegrini November 20, 2023
Hello, I am building an application using h2o but my container scanner has flagged a vulnerability for one of your Java dependencies (com.fasterxml.jackson.core). Could you please bump the version from 2.14.2 to 2.15.0 in the next release? Below you will see the output of the scanner. Thanks!

"vulnerabilities": [
{
"CVE": "PRISMA-2023-0067",
"CVSS": "7.50",
"Fixed On": "24 Apr 23 00:00 UTC",
"Link": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=PRISMA-2023-0067",
"Package Name": "com.fasterxml.jackson.core_jackson-core",
"Package Type": "Java",
"Package Version": "2.14.2",
"Severity": "high",
"Status": "fixed in 2.15.0"
}]

support ticket: https://support.h2o.ai/a/tickets/107321

@wendycwong
Copy link
Contributor Author

Duplicated in #15748

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant