Skip to content

Vulnerable Dependency in version 2.7.0 - Jackson Databind #102

@owaspdpn

Description

@owaspdpn

Hi,

Latest stable version has a dependency that has public known vulnerability:

https://github.com/delirius325/jmeter-elasticsearch-backend-listener/blob/master/pom.xml#L139

jackson-databind-2.10.0.pr1 -> CVE-2020-25649

FasterXML/jackson-databind#2589

dependency-check tool can be used to detect vulnerable dependencies:
https://owasp.org/www-project-dependency-check/

Please could you release a new version, I think rebuilding the source should fix the issue based on the maven config:
https://github.com/delirius325/jmeter-elasticsearch-backend-listener/blob/master/pom.xml#L140

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions