Skip to content

High severity CVEs in 1.17.1 #1714

@alicejgibbons

Description

@alicejgibbons

Env: Spring boot 4.0.5
SDK: 1.17.1

✗ Allocation of Resources Without Limits or Throttling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924] in com.fasterxml.jackson.core:jackson-core@2.19.2
introduced by io.dapr:dapr-sdk@1.17.0 > com.fasterxml.jackson.core:jackson-databind@2.19.2 > com.fasterxml.jackson.core:jackson-core@2.19.2 and 2 other path(s)
This issue was fixed in versions: 2.18.6, 2.21.1

✗ Allocation of Resources Without Limits or Throttling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551] in com.fasterxml.jackson.core:jackson-core@2.19.2
introduced by io.dapr:dapr-sdk@1.17.0 > com.fasterxml.jackson.core:jackson-databind@2.19.2 > com.fasterxml.jackson.core:jackson-core@2.19.2 and 2 other path(s)
This issue was fixed in versions: 2.21.2

✗ HTTP Request Smuggling [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-15789756] in io.netty:netty-codec-http@4.2.10.Final
introduced by io.dapr:dapr-sdk@1.17.0 > io.grpc:grpc-netty@1.76.0 > io.netty:netty-codec-http2@4.2.10.Final > io.netty:netty-codec-http@4.2.10.Final and 3 other path(s)
This issue was fixed in versions: 4.1.132.Final, 4.2.12.Final

Metadata

Metadata

Assignees

Labels

kind/bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions