Groups
Groups
Sign in
Groups
Groups
ehcache-users
Conversations
About
Send feedback
Help
Ehcache 2.10.10 - jackson-databind 2.11 vulnerability
441 views
Skip to first unread message
Luca Zenobi
unread,
Feb 23, 2022, 11:37:02 AM
2/23/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ehcache-users
Hi there,
I have seen that there is an unreleased branch
2.10.10
https://github.com/ehcache/ehcache2/tree/release/2.10.10
that is fixing the vulnerability detected in jackson-databind 2.11 and fixed in 2.13.1
https://github.com/FasterXML/jackson-databind/issues/3328
.
May I ask if it is planned that this branch will be publicly available in maven central and when? Is it possible / safe to push in a private artifactory and use it in production code?
Many thanks for your answers,
Luca
Reply all
Reply to author
Forward
0 new messages