Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-7525,CVE-2017-15095 and CVE-2017-17485 fix for all these vulnerabilities. #4495

Closed
samawarad opened this issue Apr 23, 2024 · 6 comments

Comments

@samawarad
Copy link

Hi team,

We have below 3 vulnerabilities reported on jackson-databind 2.2.1, 2.2.3 and 2.4.3 in 3 different components of the product. We want to maintain the same single version of jackson-databind in all 3 components which has fix for all vulnerabilities reported.

CVE-2017-7525 -> Fix available in 2.6.7.1
CVE-2017-15095 -> Fix available in 2.6.7.3
CVE-2017-17485 -> Fix available in 2.7.9.2

Can we uppgrade to 2.7.9.2?

@pjfanning
Copy link
Member

pjfanning commented Apr 23, 2024

Closing. This is an abuse of GitHub discussions. Try changing Jackson version yourself. Why are we supposed to guess what impact this will have on your code?

@cowtowncoder
Copy link
Member

cowtowncoder commented Apr 23, 2024 via email

@samawarad
Copy link
Author

Hi @cowtowncoder Thanks for updating CVE-2017-7525. Thanks for your time and support :)

@cowtowncoder
Copy link
Member

You are welcome @samawarad .

@samawarad
Copy link
Author

samawarad commented Apr 24, 2024

Closing. This is an abuse of GitHub discussions. Try changing Jackson version yourself. Why are we supposed to guess what impact this will have on your code?

I am sorry if asking a question is abuse of gtihub discussions. I am really not looking for impact on our code. One of contributor @cowtowncoder updated for CVE-2017-7525, which will really help people who are looking for fixed versions. Few details were not clear so raised this query.
Thanks for all of your time and support. Cheers!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants