Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

joss depends on jackson-mapper-asl:1.9.11 which has CVE vulnerability CVE-2019-10172 #175

Open
sxh850297968 opened this issue Apr 13, 2020 · 1 comment

Comments

@sxh850297968
Copy link

Hi firend,
joss depends on jackson-mapper-asl:1.9.11 which has
CVE vulnerability CVE-2019-10172, and jackson-mapper-asl not be updated in the past 7 years.
I hava two questions.

  1. How does the CVE vulnerability CVE-2019-10172 affect joss ? can I ignore this CVE ?
  2. Is there any plan to replace jackson-mapper-asl with other software ?
@sxh850297968
Copy link
Author

@robert-bor Please help to confirm this issue, thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant