You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The text was updated successfully, but these errors were encountered:
alexopoulos7
changed the title
Upgrade jackson-databind library of embulk-input-postgresql to 2.13
Security update of jackson-databind library of embulk-input-postgresql to 2.13
Sep 29, 2022
If we check https://github.com/embulk/embulk-input-jdbc/blob/master/embulk-input-postgresql/gradle/dependency-locks/compileClasspath.lockfile we can see that jackson-databind is in version 2.6.7 but this version has some security vulnerabilities and needs to be upgraded:
CWE-502: Deserialization of Untrusted Data
CWE-184: Incomplete List of Disallowed Inputs
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616
The text was updated successfully, but these errors were encountered: