You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Thanks, for raising this issue. Note, that the vulnerability is during deserialization of JSON data. This library uses jackson only for serialization. Nevertheless, I will upgrade the dependency and create a new library version soon.
Release
cf-java-logging-support-log4j2: 3.8.4
transitively depends onjackson-core: 2.14.2
:Library
jackson-core: 2.14.2
contains a DDoS vulnerability, see e.g.: https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538Please consider upgrading to
2.15.0
or higher.The text was updated successfully, but these errors were encountered: