Uploaded image for project: 'Build'
  1. Build
  2. BUILD-1223

Dismiss false positive CVE concerning jackson-core 2.13.5

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Not an issue
    • Icon: Neutral Neutral
    • None
    • BOM 6.2.43
    • None

      According to this notice:

      FasterXML Jackson Core is vulnerable to a denial of service, caused by improper input validation by the StreamReadConstraints value field. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.

      Notes
      It doesn't look like we use StreamReadConstraints. Probably a false positive.

      [INFO] |  +- info.magnolia.webhooks:magnolia-webhooks-core:jar:1.0.2:compile
      [INFO] |  |  +- org.antlr:antlr4-runtime:jar:4.9.2:compile
      [INFO] |  |  +- com.fasterxml.jackson.core:jackson-core:jar:2.13.5:compile
      


      The issue looks indeed like a false positive:

        Acceptance criteria

              fgrilli Federico Grilli
              rgange Richard Gange
              Foundation
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Task DoR