Commit aedb673
committed
fix(security): upgrade jackson-databind 2.17.2 -> 2.18.9 to resolve Dependabot alerts #8-12
- CVE: PolymorphicTypeValidator bypass (HIGH)
- CVE: array subtype allowlist bypass (HIGH)
- CVE: InetSocketAddress SSRF (MEDIUM)
- CVE: @JsonIgnore on Record bypass (MEDIUM)
- CVE: case-insensitive deserialization bypass (MEDIUM)
- Also: set okhttp3-extension to release version 2.0.x.202607301 parent 06ad3b0 commit aedb673
1 file changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
| 64 | + | |
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | | - | |
| 69 | + | |
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
| |||
0 commit comments