Security update for jackson-databind
Announcement ID: | SUSE-SU-2021:0243-1 |
---|---|
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves three vulnerabilities can now be installed.
Description:
This update for jackson-databind fixes the following issues:
jackson-databind was updated to 2.10.5.1:
* #2589: DOMDeserializer
: setExpandEntityReferences(false) may
not prevent external entity expansion in all cases
(CVE-2020-25649, bsc#1177616)
* #2787 (partial fix): NPE after add mixin for enum
* #2679: 'ObjectMapper.readValue("123", Void.TYPE)' throws
"should never occur"
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Development Tools Module 15-SP2
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-243=1
Package List:
-
Development Tools Module 15-SP2 (noarch)
- jackson-databind-2.10.5.1-3.3.2
References:
- https://www.suse.com/security/cve/CVE-2020-25649.html
- https://www.suse.com/security/cve/CVE-2020-35728.html
- https://www.suse.com/security/cve/CVE-2021-20190.html
- https://bugzilla.suse.com/show_bug.cgi?id=1177616
- https://bugzilla.suse.com/show_bug.cgi?id=1180391
- https://bugzilla.suse.com/show_bug.cgi?id=1181118