-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Milestone
Description
Snyk reports the following High severity vulnerability in HumanCellAtlas/data-consumer-vignettes. Please remediate by the end of Q1 Milestone 2.
Description
com.fasterxml.jackson.core:jackson-databind
Suggested Remediation
Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.10.0.pr3, 2.9.10 or higher.
Details
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Affected versions of this package are vulnerable to Deserialization of Untrusted Data. Two additional net.sf.ehcache gadgets are not blacklisted.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels