You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We use black-duck to find security vulnerabilities. The scan of the latest spring-boot 1.5.9 and 1.5.10 both show up an CVE-2017-17485 issue, sourced in jackson-databind 2.8.10.
Is there any plan to upgrade this dependency to a newer one (like 2.9.4), where the security breach was resolved?
I'd really appreciate feedback/suggestions/discussion about this.
The text was updated successfully, but these errors were encountered:
Hi!
We use black-duck to find security vulnerabilities. The scan of the latest spring-boot 1.5.9 and 1.5.10 both show up an CVE-2017-17485 issue, sourced in jackson-databind 2.8.10.
Is there any plan to upgrade this dependency to a newer one (like 2.9.4), where the security breach was resolved?
I'd really appreciate feedback/suggestions/discussion about this.
The text was updated successfully, but these errors were encountered: