Version 8.5.4 fixable vulnerability
ticteam opened this issue · 1 comments
ticteam commented
Hello,
the Version 8.5.4
which is used to build the docker image flyway:master
still has a fixable vulnerability
flyway-commandline-8.5.4\flyway-8.5.4\lib\aad\jackson-databind-2.12.6.jar
high
7.5
CVE-2020-36518
com.fasterxml.jackson.core_jackson-databind 2.12.6
fixed in: 2.13.0
10 days ago
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
could you pls fix that ?
greetings
DoodleBobBuffPants commented
This has already been updated and will be in the next release