twilio / twilio-java

A Java library for communicating with the Twilio REST API and generating TwiML.
MIT License
484 stars 425 forks source link

Dependency on a vulnerable version of Jackson Databind #679

Closed DeMack closed 2 years ago

DeMack commented 2 years ago

Issue Summary

The current version has a dependency on jackson-databind v2.12.6 which is vulnerable to this issue. Upgrading to v2.12.6.1 should correct it.

Technical details:

DeMack commented 2 years ago

It looks like this will likely be fixed by #677

childish-sambino commented 2 years ago

This issue has been added to our internal backlog to be prioritized. +1s on the issue summary will help it move up the backlog.

Dichotomia commented 2 years ago

+1

allantodd commented 2 years ago

+1