Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-42003 - ibm-cos-java-sdk-bundle 2.12.0 contains vulnerable in jackson-databind 2.13.3 #56

Closed
mkrakow opened this issue Oct 11, 2022 · 6 comments

Comments

@mkrakow
Copy link

mkrakow commented Oct 11, 2022

The library jackson-databind version 2.13.3 is embedded in the latest version 2.12.0 of ibm-cos-java-sdk-bundle .

According to GHSA-57j2-w4cx-62h2 the above version of Jackson Databind is vulnerable.

Could you please fix COS Java SDK bundle with updated Jackson Databind library to 2.14.0 ?

@IBMalok
Copy link
Contributor

IBMalok commented Oct 13, 2022

@mkrakow - Thanks for your report. We have an internal ticket to complete this work.

@tcherel
Copy link

tcherel commented Oct 21, 2022

@IBMalok do you have an idea when that will be completed?
Jackson Databind library to 2.14.0 is not GA yet but 2.13.4.2 (already GA) contains all the fixes need for this vulnerability (as well as some of the recent new ones (https://nvd.nist.gov/vuln/detail/CVE-2022-42003 and https://nvd.nist.gov/vuln/detail/CVE-2022-42004).

@IBMalok
Copy link
Contributor

IBMalok commented Oct 26, 2022

@tcherel - We're going to release soon.

@IBMalok
Copy link
Contributor

IBMalok commented Nov 3, 2022

@mkrakow @tcherel - We have released 2.12.1 to address this issue. Please verify and close this ticket.

@IBMalok
Copy link
Contributor

IBMalok commented Nov 17, 2022

Closing this issue as resolved.

@IBMalok IBMalok closed this as completed Nov 17, 2022
@tcherel
Copy link

tcherel commented Nov 17, 2022

@IBMalok my apologies, forgot to update the git issue to confirm that the issue is indeed fixed.
Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants