Skip to content

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Aug 5, 2025

This PR contains the following updates:

Package Type Update Change
com.fasterxml.jackson.core:jackson-databind (source) dependencies minor 2.9.9 -> 2.12.7.1

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
Critical Critical 9.8 CVE-2019-14540
Critical Critical 9.8 CVE-2019-14892
Critical Critical 9.8 CVE-2019-16942
Critical Critical 9.8 CVE-2019-16943
Critical Critical 9.8 CVE-2019-17267
Critical Critical 9.8 CVE-2019-20330
High High 8.8 CVE-2020-10672
High High 8.8 CVE-2020-10673
High High 8.8 CVE-2020-10968
High High 8.8 CVE-2020-10969
High High 8.8 CVE-2020-11111
High High 8.8 CVE-2020-11112
High High 8.8 CVE-2020-11113
High High 8.1 CVE-2020-10650
High High 8.1 CVE-2020-11619
High High 8.1 CVE-2020-11620
High High 8.1 CVE-2020-14060
High High 8.1 CVE-2020-14061
High High 8.1 CVE-2020-14062
High High 8.1 CVE-2020-14195
High High 8.1 CVE-2020-24616
High High 7.5 CVE-2022-42003
High High 7.5 CVE-2022-42004
High High 7.5 CVE-2025-52999
High High 7.5 WS-2022-0468
Medium Medium 5.9 CVE-2019-12814

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Aug 5, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/master-com.fasterxml.jackson.core-jackson-databind-2.x branch from 51bdfee to ae0f4f5 Compare December 4, 2025 19:24
@mend-for-github-com mend-for-github-com bot changed the title Update dependency com.fasterxml.jackson.core:jackson-databind to v2.12.7.1 (master) Update dependency com.fasterxml.jackson.core:jackson-databind to v2.10.2 (master) Dec 4, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/master-com.fasterxml.jackson.core-jackson-databind-2.x branch from ae0f4f5 to 0464b0e Compare December 6, 2025 13:00
@mend-for-github-com mend-for-github-com bot changed the title Update dependency com.fasterxml.jackson.core:jackson-databind to v2.10.2 (master) Update dependency com.fasterxml.jackson.core:jackson-databind to v2.12.7.1 (master) Dec 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant