Skip to content

Is jackson 2.13.x going to receive a patch for CVE-2022-42003? #126

Closed Answered by cowtowncoder
jsadn asked this question in Q&A
Discussion options

You must be logged in to vote

No plans for backporting at this point.

EDIT: the main reason for not backporting is since this is technically behavioral change that could break some usage; specifically if some code assumes that multiple nested Arrays may be used (and unwrapped). Since the likelihood seems small (and there being a security issue) I am comfortable changing this -- without any way to to use old behavior -- in a minor release, but less so in a patch.

Replies: 4 comments 7 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
5 replies
@pinpan
Comment options

@pjfanning
Comment options

@pinpan
Comment options

@cowtowncoder
Comment options

@pinpan
Comment options

Answer selected by jsadn
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@jsadn
Comment options

@cowtowncoder
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants