Replies: 1 comment 1 reply
-
Dropwizard Metrics 4.2.x is already using Jackson 2.12.7 which is not affected by this vulnerability.
We won't upgrade the Jackson version in Dropwizard Metrics 4.1.x, but you can override the version of Jackson being used in your project by adding the respective artifacts into the |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We are having to update our own dependencies because of a vulnerability in
jackson-databind
and this project is one of our direct dependencies which led to it being included in the first place, so you may want to update your jackson versions as well.https://nvd.nist.gov/vuln/detail/CVE-2020-36518
Beta Was this translation helpful? Give feedback.
All reactions