sendgrid / sendgrid-java

The Official Twilio SendGrid Led, Community Driven Java API Library
https://sendgrid.com
MIT License
483 stars 408 forks source link

chore: bump jackson-databind from 2.13.3 to 2.13.4.2 #738

Closed wkurniawan07 closed 8 months ago

wkurniawan07 commented 1 year ago

Fixes

Updates jackson-related libraries to 2.13.4 or 2.13.4.2 (latest version for 2.13). This mitigates CVE-2022-42003 and CVE-2022-42002.

rogierslag commented 8 months ago

We'd also be interested in this release, as Jackson 2.13.3 has 3 open CVEs

Note that 2.13.4.2 is still vulnerable for the last one, best would be an update to 2.16.1

tiwarishubham635 commented 8 months ago

Hello! I am from twilio and I have looked at this PR. I created #745 that will be addressing this issue. Closing this PR here. Please create a new issue if further assistance is needed. Thanks!