Re: [jackson-user] Jackson-Databind 2.10 / 3.x Vulnerabilities (CVE's) Fix

2019-07-29 Thread Andi Egloff
Hi Tatu, As background to my questions, I'm guessing we're not the only ones that have been forced to keep up with the arms race of steady flow of CVEs and fixes in our products; even if it isn't actually exploitable in the way we use it, customers will not accept libraries to be present with k

Re: [jackson-user] Jackson-Databind 2.10 / 3.x Vulnerabilities (CVE's) Fix

2019-07-29 Thread Tatu Saloranta
On Mon, Jul 29, 2019 at 3:22 PM Andi Egloff wrote: > Hi Tatu, > As background to my questions, I'm guessing we're not the only ones that > have been forced to keep up with the arms race of steady flow of CVEs and > fixes in our products; even if it isn't actually exploitable in the way we > use i