Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2018-1000873 via Jackson 2.8.11 in Spring 4 [SPR-17656] #22185

Closed
spring-projects-issues opened this issue Jan 9, 2019 · 1 comment
Closed
Assignees
Labels
status: invalid An issue that we don't feel is valid

Comments

@spring-projects-issues
Copy link
Collaborator

GFriedrich opened SPR-17656 and commented

Hi,

I just got aware of the CVE-2018-1000873. Unfortunately it affects all versions of Jackson < 2.9.8.
As far as I can see, Spring 4 uses version 2.8.11 as optional dependency. So I guess it would be safe to update the version without breaking Spring. Is my assumption correct?
If so: Are you planning to update the Jackson version for the Spring 4.x branch and create a release?

Thanks in advance for any info.


Affects: 4.3.22

@spring-projects-issues spring-projects-issues added status: waiting-for-triage An issue we've not yet triaged or decided on type: task A general task labels Jan 11, 2019
@bclozel bclozel self-assigned this Jan 11, 2019
@bclozel bclozel added status: invalid An issue that we don't feel is valid and removed status: waiting-for-triage An issue we've not yet triaged or decided on type: task A general task labels Jan 11, 2019
@bclozel
Copy link
Member

bclozel commented Jan 11, 2019

Closing this issue as this was addressed in spring-projects/spring-boot#15664

@bclozel bclozel closed this as completed Jan 11, 2019
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
status: invalid An issue that we don't feel is valid
Projects
None yet
Development

No branches or pull requests

2 participants