flyway/flyway-docker

Version 8.5.4 fixable vulnerability

ticteam opened this issue · 1 comments

Hello,
the Version 8.5.4
which is used to build the docker image flyway:master

still has a fixable vulnerability
flyway-commandline-8.5.4\flyway-8.5.4\lib\aad\jackson-databind-2.12.6.jar

high
7.5
CVE-2020-36518
com.fasterxml.jackson.core_jackson-databind 2.12.6
fixed in: 2.13.0
10 days ago

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

could you pls fix that ?
greetings

This has already been updated and will be in the next release