microsoft / Partner-Center-Java

Partner Center SDK for Java
https://docs.microsoft.com/java/partnercenter/
31 stars 12 forks source link

There is a vulnerability in jackson-databind 2.10.3,upgrade recommended #140

Open QiAnXinCodeSafe opened 3 years ago

QiAnXinCodeSafe commented 3 years ago

https://github.com/microsoft/Partner-Center-Java/blob/cb7c53f7abc84b3a3b9708c933f6bf9a1e3bc47a/pom.xml#L89

CVE-2020-25649

Recommended upgrade version: 2.10.5.1