Update dependency com.fasterxml.jackson.core:jackson-databind to v2.13.5 #136
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
| CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
WS-2022-0468Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.13.5/d07c97d3de9ea658caf1ff1809fd9de930a286a/jackson-core-2.13.5.jar Dependency Hierarchy: -> aws-java-sdk-core-1.12.651.jar (Root Library) -> jackson-dataformat-cbor-2.13.5.jar -> ❌ jackson-core-2.13.5.jar (Vulnerable Library) |
7.5 | jackson-core-2.13.5.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 | #134 | |
WS-2022-0468Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.13.5/d07c97d3de9ea658caf1ff1809fd9de930a286a/jackson-core-2.13.5.jar Dependency Hierarchy: -> jackson-databind-2.13.5.jar (Root Library) -> ❌ jackson-core-2.13.5.jar (Vulnerable Library) |
7.5 | jackson-core-2.13.5.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 | None |
✔️ Remediated vulnerabilities:
| CVE | Vulnerable Library |
|---|---|
| WS-2022-0468 | jackson-core-2.13.4.jar |
Base branch total remaining vulnerabilities: 4
Base branch commit: 9746f56b6cb92c982c2220b6a8b2c6a09ec63eee
Total libraries scanned: 51
Scan token: d28a07900b484fb7af837db9e6c2cdcb