Is your feature request related to a problem? Please describe.
google-cloud-storage:2.75.0 (the latest version currently published on Maven Central) declares a transitive and direct dependency on
com.fasterxml.jackson.core:jackson-databind:2.18.3 (along with jackson-core, jackson-annotations, and jackson-dataformat-xml at the same version).
Jackson-databind 2.18.3 is affected by several publicly disclosed CVEs, which our internal AppSec / SCA pipeline flags and which is currently blocking our
build whenever we add google-cloud-storage as a dependency.
Describe the solution you'd like
Bump the managed jackson-databind version (and matching jackson-core / jackson-annotations) in the google-cloud-storage POM/BOM to at least 2.18.9,
or to a current patched release on the 2.21.x line, so that consumers are not forced to override the transitive Jackson version manually to pass security
scanning.
Describe alternatives you've considered
We could manually pin a patched jackson-databind version via dependency constraints/BOM overrides in our own build, but this has to be repeated by every
consumer of google-cloud-storage and does not fix the issue at the source.
Additional context
- Affected artifact:
com.google.cloud:google-cloud-storage, version 2.75.0
- Transitive dependency:
com.fasterxml.jackson.core:jackson-databind:2.18.3
- Known vulnerabilities in jackson-databind 2.18.3:
- Insecure deserialization issue, fixed in 2.18.8 / 2.21.4 / 3.1.4
- DNS query vulnerability via
InetSocketAddress, fixed in 2.18.8 / 2.21.4 / 3.1.4
- Case-insensitive binding that reopens fields marked with
@JsonIgnore, fixed in 2.18.9 / 2.21.5 / 3.1.4
- Build tool: Maven/Gradle
Is your feature request related to a problem? Please describe.
google-cloud-storage:2.75.0(the latest version currently published on Maven Central) declares a transitive and direct dependency oncom.fasterxml.jackson.core:jackson-databind:2.18.3(along withjackson-core,jackson-annotations, andjackson-dataformat-xmlat the same version).Jackson-databind 2.18.3 is affected by several publicly disclosed CVEs, which our internal AppSec / SCA pipeline flags and which is currently blocking our
build whenever we add
google-cloud-storageas a dependency.Describe the solution you'd like
Bump the managed
jackson-databindversion (and matchingjackson-core/jackson-annotations) in thegoogle-cloud-storagePOM/BOM to at least2.18.9,or to a current patched release on the 2.21.x line, so that consumers are not forced to override the transitive Jackson version manually to pass security
scanning.
Describe alternatives you've considered
We could manually pin a patched
jackson-databindversion via dependency constraints/BOM overrides in our own build, but this has to be repeated by everyconsumer of
google-cloud-storageand does not fix the issue at the source.Additional context
com.google.cloud:google-cloud-storage, version2.75.0com.fasterxml.jackson.core:jackson-databind:2.18.3InetSocketAddress, fixed in 2.18.8 / 2.21.4 / 3.1.4@JsonIgnore, fixed in 2.18.9 / 2.21.5 / 3.1.4