Skip to content

Commit

Permalink
Bump version of Jackson libraries to 2.15.2
Browse files Browse the repository at this point in the history
Previous versions of Jackson libraries included an old version of
snakeyaml which was susceptible to CVE-2022-1471.
  • Loading branch information
avelanarius authored Jul 11, 2023
1 parent cd6b641 commit d291df6
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 5 deletions.
4 changes: 4 additions & 0 deletions driver-core/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,10 @@
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-core</artifactId>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
Expand Down
8 changes: 3 additions & 5 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -61,9 +61,7 @@
<snappy.version>1.1.2.6</snappy.version>
<lz4.version>1.4.1</lz4.version>
<hdr.version>2.1.10</hdr.version>
<jackson.version>2.8.11</jackson.version>
<!-- jackson-databind 2.7.x is the last to support java 6 -->
<jackson-databind.version>2.7.9.7</jackson-databind.version>
<jackson.version>2.15.2</jackson.version>
<joda.version>2.9.9</joda.version>
<jsr353-api.version>1.0</jsr353-api.version>
<jsr353-ri.version>1.0.4</jsr353-ri.version>
Expand Down Expand Up @@ -202,7 +200,7 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson-databind.version}</version>
<version>${jackson.version}</version>
</dependency>

<dependency>
Expand Down Expand Up @@ -560,7 +558,7 @@
<additionalDependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson-databind.version}</version>
<version>${jackson.version}</version>
</additionalDependency>
<additionalDependency>
<groupId>joda-time</groupId>
Expand Down

0 comments on commit d291df6

Please sign in to comment.