jackson-databind 2.9.10.5 in metrics-json still has security vulnerabilities,please upgrade to 2.10.3 or higher
envgap__dropwizard__metrics-1706
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
5a6926bb6ddc514e6ea767448a373e087d7d69f0- Manifest
metrics-json/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
dropwizard/metrics #1706 · read the original issue
hi jackson-databind 2.9.10.5 in metrics-json still has security vulnerabilities,please upgrade to 2.10.3 or higher security vulnerabilities: CVE-2020-24750/CVE-2020-24616 Thanks Shirley
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]