Skip to content

Update dependency com.fasterxml.jackson.core:jackson-databind to v2.13.5

290f50d
Select commit
Loading
Failed to load commit list.
Merged

Update dependency com.fasterxml.jackson.core:jackson-databind to v2.13.5 #136

Update dependency com.fasterxml.jackson.core:jackson-databind to v2.13.5
290f50d
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Apr 15, 2025 in 2m 55s

Security Report

You have successfully remediated 1 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
WS-2022-0468

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.13.5/d07c97d3de9ea658caf1ff1809fd9de930a286a/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> aws-java-sdk-core-1.12.651.jar (Root Library)

   -> jackson-dataformat-cbor-2.13.5.jar

     -> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High 7.5 jackson-core-2.13.5.jar Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 #134
WS-2022-0468

Path to dependency file: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.13.5/d07c97d3de9ea658caf1ff1809fd9de930a286a/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> jackson-databind-2.13.5.jar (Root Library)

   -> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High 7.5 jackson-core-2.13.5.jar Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
WS-2022-0468 jackson-core-2.13.4.jar

Base branch total remaining vulnerabilities: 4
Base branch commit: 9746f56b6cb92c982c2220b6a8b2c6a09ec63eee


Total libraries scanned: 51

Scan token: d28a07900b484fb7af837db9e6c2cdcb