googleapis / google-http-java-client

Google HTTP Client Library for Java
Apache License 2.0
1.39k stars 451 forks source link

Dependency: DOS issue reported by Snyk with outdated jackson-core version 2.14.2 #1966

Closed elevenfive closed 1 month ago

elevenfive commented 3 months ago

Thanks for stopping by to let us know something could be better!

PLEASE READ: If you have a support contract with Google, please create an issue in the support console instead of filing on GitHub. This will ensure a timely response.

Please run down the following list and make sure you've tried the usual "quick fixes":

If you are still having issues, please include as much information as possible:

Environment details

  1. Specify the API at the beginning of the title. For example, "BigQuery: ..."). General, Core, and Other are also allowed as types
  2. OS type and version: N/A
  3. Java version: N/A
  4. version(s): 1.44.2 (current a/o 2024-06-26) and earlier

Steps to reproduce

  1. N/A - pom is out of date

Code example

N/A

Stack trace

N/A

External references such as API reference guides

https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538

Any additional information below

N/A

Following these steps guarantees the quickest resolution possible.

Thanks!

ldetmer commented 1 month ago

Thanks! The latest release (1.45.0) has jackson upgraded to 2.17.2