-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Has CVE-2018-1000873 been fixed in Jackson 2.x? [clue: yes!] #2298
Comments
I don't know what CVE-2018-1000873 is without looking. It would be good to link to it, and/or explain briefly what it is. I'll have a look. |
@mldz100820 Did you actually read the description at https://nvd.nist.gov/vuln/detail/CVE-2018-1000873 ? It says:
Further, there is Jackson issue filed for this although on different repo: FasterXML/jackson-modules-java8#90 which makes as per what CVE says. |
Thank you for your reply ! Actually, I've read this already. |
@mldz100820 Jackson-jsr310 has a dependency on databind yes. But specific CVE only affects Instant/Duration handling as fully implemented by jsr310 module -- without it, databind would attempt to deal with them as POJOs and that would not trigger issue (also would not work very well for any use). Security analysis tools appears to be crocks full of shite (as Kurt Vonnegut would put it), in general for they do not have enough context, knowledge, and authors do not have to care about accuracy. Money is brought in by people with good intentions who assume that tools know what they are doing :-p |
Please, has CVE-2018-1000873 been repaired in Jackson 2.10.0?
In addition, when can the official version of Jackson 2.10.0 be downloaded at https://mvnrepository.com/?
Thank you in advance.
The text was updated successfully, but these errors were encountered: