Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] [JAVA] [SECURITY] jackson-databind 2.13.1 #13388

Closed
5 of 6 tasks
embenzekri opened this issue Sep 8, 2022 · 0 comments · Fixed by #13391
Closed
5 of 6 tasks

[BUG] [JAVA] [SECURITY] jackson-databind 2.13.1 #13388

embenzekri opened this issue Sep 8, 2022 · 0 comments · Fixed by #13391

Comments

@embenzekri
Copy link

embenzekri commented Sep 8, 2022

Bug Report Checklist

  • Have you provided a full/minimal spec to reproduce the issue?
  • Have you validated the input using an OpenAPI validator (example)?
  • Have you tested with the latest master to confirm the issue still exists?
  • Have you searched for related issues/PRs?
  • What's the actual output vs expected output?
  • [Optional] Sponsorship to speed up the bug fix or feature request (example)
Description

I'm contacting you regarding the CVE-2020-36518 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36518.
As openapi-generator-cli is using jackson-databind 2.13.1 which is vulnerable to this issue, are you tacking into account an upgrade of jackson-databind please?

openapi-generator version

openapi-generator-cli 6.0.1

Suggest a fix

Upgrade jackson-databind as the issue is fixed in 2.13.2.2 by this commit, and in 2.12.6.1 by this commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant