You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Comments on closed issues are hard for our team to see.
If you need more assistance, please open a new issue that references this one.
If you wish to keep having a conversation with other community members under this issue feel free to do so.
Describe the bug
The shaded third-party
jackson-core
is set at version2.13.2
which does not have a fix for vulnerability issuesonatype-2022-6438
.aws-sdk-java-v2/pom.xml
Line 95 in 5aa3ff3
Expected Behavior
The shaded third-party
jackson-core
should be at least version2.15.0
.Current Behavior
The issue was flagged by a prisma scan.
Reproduction Steps
N/A
Possible Solution
Upgrade to at least 2.15.0. Hopefully this is not too difficult because of the shading.
From #2598 (comment):
Additional Information/Context
See:
StreamReadConstraints
(fixessonatype-2022-6438
) -- default 1000 chars FasterXML/jackson-core#827This issue is similar to: #3825
AWS Java SDK version used
2.18.41
JDK version used
openjdk version "1.8.0_382" OpenJDK Runtime Environment Corretto-8.382.05.1 (build 1.8.0_382-b05) OpenJDK 64-Bit Server VM Corretto-8.382.05.1 (build 25.382-b05, mixed mode)
Operating System and version
Linux 9d7c897afc63 6.4.11-arch2-1 #1 SMP PREEMPT_DYNAMIC Sat, 19 Aug 2023 15:38:34 +0000 x86_64 x86_64 x86_64 GNU/Linux
The text was updated successfully, but these errors were encountered: