-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Block two more gadget types (commons-dbcp, p6spy, CVE-2019-16942 / CVE-2019-16943) #2478
Comments
Email received (read that before seeing this issue). |
@cowtowncoder I think you have the Milstone of 2.9.10 wrong on this ticket as it was fixed after 2.9.10. Wouldn't it be 2.9.10.1 ? |
@melloware Yes, you are right. Will fix the milestone, for some reason set it incorrectly (possibly due to auto-completion). |
by upgrading dependency jackson-databind/ to 2.10.0: FasterXML/jackson-databind#2478
by upgrading dependency jackson-databind/ to 2.10.0 FasterXML/jackson-databind#2478
@cowtowncoder Is there a planned release date for 2.9.10.1? |
There is no strict rule; ideally I'd want more than just one fix in a new release, but I understand that for CVEs there is bit more urgency. Since 2.9.10 was released on September 21, I think realistic timeline would be within October. So I am thinking of releasing a micro-patch by end of next week, so around 19th or so. |
Thanks @cowtowncoder. That sounds reasonable. |
@cowtowncoder, will there be an updated |
@msymons I regret to tell you,the risk occur with older versions of dbcp,dbcp2. |
- CVE-2019-16942 - CVE-2019-16943 FasterXML/jackson-databind#2478 Signed-off-by: Antony O'Neill <antony@boclips.com>
@msymons yes, I plan to also publish matching |
Another 2 gadget (*) types reported regarding classes of
commons-dbcp
andp6spy
packages.See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Mitre id: CVE-2019-16942 (commons-dbcp)
Mitre id: CVE-2019-16943 (p6spy)
Reporter: b5mali4
Fixed in:
jackson-bom
version2.9.10.20191020
)The text was updated successfully, but these errors were encountered: