Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2.11.0 CVE CVE 2022 42003 #4473

Closed

Conversation

SealSagish
Copy link

No description provided.

@SealSagish SealSagish changed the base branch from 2.18 to 2.11 April 7, 2024 16:54
@pjfanning
Copy link
Member

pjfanning commented Apr 7, 2024

Why don't you upgrade Jackson? The actual fix for CVE-2022-42003 is in 2.12.7.1 (see https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12) - not a big upgrade from Jackson 2.11.
I would be against backporting this different fix to 2.11.

@JooHyukKim
Copy link
Member

JooHyukKim commented Apr 7, 2024

2.11 is no longer patched. Either forking 2.11 version or an upgrade(forgot the version) will do.

@cowtowncoder
Copy link
Member

cowtowncoder commented Apr 7, 2024

What is this even? Are you kidding?

No, there's no backporting of new features against SemVer, especially for long-ago closed branch.

So the fix really is to upgrade to a later version, as indicated in #3590 .

@cowtowncoder
Copy link
Member

cowtowncoder commented Apr 7, 2024

Why don't you upgrade Jackson? The actual fix for CVE-2022-42003 is in 2.12.7.1 - not a big upgrade from Jackson 2.11. I would be against backporting this different fix to 2.11.

Absolutely agreed.

@SealSagish SealSagish deleted the 2.11.0-CVE-CVE-2022-42003 branch April 8, 2024 06:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants