-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Two more c3p0
gadgets to exploit default typing issue [CVE-2018-7489] #1931
#1984
Comments
If I interpret the #1972 (comment) from @cowtowncoder I think it should be release this month. |
@DKumars Please do not use issue tracker for asking questions. This is literally what mailing lists are for:
(or jackson-dev) As to 2.9.5, release is starting now and all components should be available within next 24 hours, excluding Scala module (which takes longer as there's no active maintainer). |
Thanks for your response, Please share the link from where i can find
official release for this fix.
…On Mon, Mar 26, 2018 at 9:08 PM, Tatu Saloranta ***@***.***> wrote:
@DKumars <https://github.com/DKumars> Please do not use issue tracker for
asking questions. This is literally what mailing lists are for:
https://groups.google.com/forum/#!forum/jackson-user
(or jackson-dev)
As to 2.9.5, release is starting now and all components should be
available within next 24 hours, excluding Scala module (which takes longer
as there's no active maintainer).
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#1984 (comment)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AEamLupg-2gBY08LFrUKz5eA0klhoeS2ks5tiQt2gaJpZM4S6vdM>
.
--
-regards,
Dharmendra
|
@DKumars Have you checked both the public maven repositories and the releases button on github? |
Its visible at https://mvnrepository.com/ but not at https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind. |
Yes, Maven Central is where releases always go. Announcements are done on Twitter ( |
Hi Team ,
As we are using jackson-databind 2.9.4 in our production system and we got one vulnerability in it
"Two more
c3p0
gadgets to exploit default typing issue [CVE-2018-7489] #1931" as mentioned in #1931 tag. For this fix , please let us know when we can have new release like 2.9.5 or patch for this fix as 2.9.4.1and its now very important for our product. Please help to share new release date for this fix.-Regards,
Dharmendra
The text was updated successfully, but these errors were encountered: