microsoft / vsts-authentication-library-for-java

Retrieve OAuth2 or Personal Accesss Tokens for Visual Studio Team Services (visualstudio.com) accounts. Also provides secure storage for those secrets on different platforms.
MIT License
18 stars 20 forks source link

There is a vulnerability in jackson-databind 2.4.1,upgrade recommended #34

Open QiAnXinCodeSafe opened 3 years ago

QiAnXinCodeSafe commented 3 years ago

https://github.com/microsoft/vsts-authentication-library-for-java/blob/edee296b96cec09dfc8af85afa0f6f348fa4920a/pom.xml#L85

CVE-2020-9547 CVE-2018-14719 CVE-2018-14718 CVE-2019-14379 CVE-2019-20330 CVE-2019-16943

Recommended upgrade version:2..3