vipshop / Saturn

The vip.com's distributed job scheduling platform.
Apache License 2.0
2.28k stars 701 forks source link

There is a vulnerability in jackson 2.9.7,upgrade recommended #727

Open QiAnXinCodeSafe opened 3 years ago

QiAnXinCodeSafe commented 3 years ago

https://github.com/vipshop/Saturn/blob/032796b7036d53f09a75de0a13808e48dce210f7/pom.xml#L73

CVE-2020-9546 CVE-2018-19360 CVE-2018-19361 CVE-2018-19362 CVE-2019-14379 CVE-2019-14540

Recommended upgrade version:2.9.10.6