-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2023-35116: jackson-databind package versions before 2.15.2 are vulnerable to Denial of Service (DoS) #63
Comments
This will be addressed and will release a new version shortly |
will next version address https://nvd.nist.gov/vuln/detail/CVE-2023-35116 ? |
@kashok7474 yes, you can take a look at this FasterXML/jackson-databind#3972 (comment) |
@avinash1IBM do you have an ETA for the new cos SDK version with the jackson-databind upgrade? |
@tcherel The most recent update from the jackson-databind team is that this is not a vulnerability. you can read this here. So even the nvd website added this note below. |
@avinash1IBM unfortunately this is not that simple. |
We will do a new release that upgrades the above dependency |
A new version of ibm-cos-sdk-java is released to address this vulnerability. Can you please close this issue. |
Thanks @avinash1IBM |
See FasterXML/jackson-databind#3972 and https://nvd.nist.gov/vuln/detail/CVE-2023-35116
It requires an upgrade to jackson-databind 2.15.3
Can it be done for the COS SDK?
Thanks.
The text was updated successfully, but these errors were encountered: