Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ibm-cos-java-sdk-bundle 2.11.1 contains vulnerable jackson-databind 2.13.1 #52

Closed
klajok opened this issue Mar 28, 2022 · 9 comments
Closed

Comments

@klajok
Copy link

klajok commented Mar 28, 2022

The library jackson-databind version 2.13.1 is embedded in the latest version 2.11.1 of ibm-cos-java-sdk-bundle .

According to GHSA-57j2-w4cx-62h2 the above version of Jackson Databind is vulnerable.

Please prepare new release of COS Java SDK bundle with updated Jackson Databind library.

@IBMeric
Copy link
Member

IBMeric commented Mar 29, 2022

Thanks for your report. We have an internal ticket to complete this work.

@hbornstein747
Copy link

Do you have an ETA when the new version will be available?

@hbornstein747
Copy link

Latest CVE requires update to 2.13.2.2. Hopefully this will be included. (I am with the the CP4D dev team)

@avinash1IBM
Copy link
Member

Thank for the update. This change will be included in the next release. Thanks

@hbornstein747
Copy link

hbornstein747 commented Apr 18, 2022

Thanks Avinash - can you tell me when that is?

@avinash1IBM
Copy link
Member

Hello,
The next release will be in second quarter.
Thanks.

@IBMeric
Copy link
Member

IBMeric commented Apr 26, 2022

@klajok @hbornstein747 We have released 2.11.2 to address this issue. Please verify and close this ticket.

@hbornstein747
Copy link

Thank you. I can verify the issue is resolved.

@klajok
Copy link
Author

klajok commented May 2, 2022

Thank you.

@klajok klajok closed this as completed May 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants