Upgrade jackson-databind to 2.9.10.3
envgap__jwtk__jjwt-567
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
e115085b14fbcaeca8445b545c8ee948d28a9cad- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
jwtk/jjwt #567 · read the original issue
`jjwt-jackson` depends on `jackson-databind` 2.9.10.1 as seen in the [pom](https://github.com/jwtk/jjwt/blob/e115085b14fbcaeca8445b545c8ee948d28a9cad/pom.xml#L100).
Running
mvn org.owasp:dependency-check-maven:5.3.0:check
results in
> jackson-databind-2.9.10.1.jar
> pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.10.1,
> cpe:2.3:a :fasterxml:jackson:2.9.10.1:*:*:*:*:*:*:*,
> cpe:2.3:a :fasterxml:jackson-databind:2.9.10.1:*:*:*:*:*:*:*) :
> CVE-2019-20330,
> CVE-2020-8840
Links to the NVD entries:
* https://nvd.nist.gov/vuln/detail/CVE-2019-20330
* https://nvd.nist.gov/vuln/detail/CVE-2020-8840
Upgrading to at least 2.9.10.2 fixes it. The latest version is at this point in time 2.9.10.3 or 2.10.2
```xml
<!-- https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind -->
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.9.10.3</version>
</dependency>
```04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]