-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Block two more gadgets to exploit default typing issue (c3p0, CVE-2018-7489) #1931
Comments
c3p0
gadgets to exploit default typing issue
Fixed in |
Hi there! This is preventing me from upgrading to 2.8.11.1 because that artifact would be required by Spring boots dependency management. Thanks in advance! |
@philippn Because beyond 2.8.11.1 there is no full release, and it is not really practical to create one-off bom sets: there may or may not be micro-patches for various components. What you need to do is to either use |
Thanks for the clarification! |
@philippn np. And apologies for the mess. I understand it is not ideal, and I am hoping we can figure out a more maintainable system for CVE updates. |
c3p0
gadgets to exploit default typing issuec3p0
gadgets to exploit default typing issue [CVE-2018-7489]
Vuln reported as: https://access.redhat.com/security/cve/cve-2018-7489 |
Hi! Any estimates for a 2.9.5 release? Thanks! |
Hi FasterXML Team , -thanks |
Is this defect applicable for org.codehaus.jackson libraries too? |
c3p0
gadgets to exploit default typing issue [CVE-2018-7489]
From an email report there are 2 other c3p0 classes (above and beyond ones listed in #1737) need to be blocked.
EDIT 21-Jun-2021: Fix included in:
2.9.5
2.8.11.1
2.7.9.3
2.6.7.5
The text was updated successfully, but these errors were encountered: