From 9aa665f0617140bb561a83144af957c9e7a983b8 Mon Sep 17 00:00:00 2001 From: Piotr Grabowski Date: Tue, 11 Jul 2023 13:19:41 +0200 Subject: [PATCH] Bump version of Jackson libraries to 2.15.2 Previous versions of Jackson libraries included an old version of snakeyaml which was susceptible to CVE-2022-1471. --- driver-core/pom.xml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/driver-core/pom.xml b/driver-core/pom.xml index e6ec0b5d283..ae6a90797f9 100644 --- a/driver-core/pom.xml +++ b/driver-core/pom.xml @@ -167,10 +167,12 @@ com.fasterxml.jackson.core jackson-databind + 2.15.2 com.fasterxml.jackson.dataformat jackson-dataformat-yaml + 2.15.2