From 1d55c19bebe6844dac126532da003414b893e356 Mon Sep 17 00:00:00 2001 From: Pratim SC Date: Thu, 10 Nov 2022 08:41:52 +0000 Subject: [PATCH] Updated Jackson data bind to version 2.13.4.2 for fixing CVE-2022-42004 --- LICENSE-binary | 2 +- gradle/dependencies.gradle | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/LICENSE-binary b/LICENSE-binary index 0409881b21e2a..a3f860e62b70d 100644 --- a/LICENSE-binary +++ b/LICENSE-binary @@ -210,7 +210,7 @@ commons-cli-1.4 commons-lang3-3.12.0 jackson-annotations-2.13.4 jackson-core-2.13.4 -jackson-databind-2.13.4 +jackson-databind-2.13.4.2 jackson-dataformat-csv-2.13.4 jackson-dataformat-yaml-2.13.4 jackson-datatype-jdk8-2.13.4 diff --git a/gradle/dependencies.gradle b/gradle/dependencies.gradle index 0d04b0e89c7d7..66ed94fea417d 100644 --- a/gradle/dependencies.gradle +++ b/gradle/dependencies.gradle @@ -67,7 +67,7 @@ versions += [ httpclient: "4.5.13", easymock: "4.3", jackson: "2.13.4", - jacksonDatabind: "2.13.4", + jacksonDatabind: "2.13.4.2", jacoco: "0.8.7", javassist: "3.27.0-GA", jetty: "9.4.48.v20220622",