[ https://issues.apache.org/jira/browse/CURATOR-683?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Kezhu Wang resolved CURATOR-683. -------------------------------- Fix Version/s: 5.6.0 Resolution: Fixed master: 26a7e4ded1d45df875ea7e9d8c311b0c1f68ad30 author: [~slavikca] I can't assign to [~slavikca] due to permission issue. > Update dependencies: com.fasterxml.jackson.core > ----------------------------------------------- > > Key: CURATOR-683 > URL: https://issues.apache.org/jira/browse/CURATOR-683 > Project: Apache Curator > Issue Type: Task > Affects Versions: 5.5.0 > Reporter: Slavik > Assignee: Enrico Olivelli > Priority: Major > Fix For: 5.6.0 > > > There are 2 com.fasterxml.jackson.core dependencies: > * jackson-core > * > jackson-databind > Both are at version 2.10.0 > These dependencies bring CVEs: > * [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42004] (resource > exhaustion) > * [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42003] (resource > exhaustion) > * [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46877] (denial of > service) > * [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36518] (denial of > service) > * [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25649] (data > integrity) > -- This message was sent by Atlassian Jira (v8.20.10#820010)