Uploaded image for project: 'Common Controller SDK'
  1. Common Controller SDK
  2. CCSDK-970

CVE-2017-4995 - jackson-datatype has incomplete fix

XMLWordPrintable

      jackson-datatype is vulnerable to CVE-2017-4995.  There is no non-vulnerable version of this library.  Workaround is not to use default typing (see https://github.com/FasterXML/jackson-docs/wiki/JacksonPolymorphicDeserialization)

            djtimoney Dan Timoney
            djtimoney Dan Timoney
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: