Visitar URL original
Transitive jackson-databind 2.18.3 dependency affected by multiple known CVEs · Issue #14606 · googleapis/google-cloud-java · GitHub
Skip to content

Transitive jackson-databind 2.18.3 dependency affected by multiple known CVEs #14606

Description

@JorgeMDO

Is your feature request related to a problem? Please describe.
google-cloud-storage:2.75.0 (the latest version currently published on Maven Central) declares a transitive and direct dependency on
com.fasterxml.jackson.core:jackson-databind:2.18.3 (along with jackson-core, jackson-annotations, and jackson-dataformat-xml at the same version).
Jackson-databind 2.18.3 is affected by several publicly disclosed CVEs, which our internal AppSec / SCA pipeline flags and which is currently blocking our
build whenever we add google-cloud-storage as a dependency.

Describe the solution you'd like
Bump the managed jackson-databind version (and matching jackson-core / jackson-annotations) in the google-cloud-storage POM/BOM to at least 2.18.9,
or to a current patched release on the 2.21.x line, so that consumers are not forced to override the transitive Jackson version manually to pass security
scanning.

Describe alternatives you've considered
We could manually pin a patched jackson-databind version via dependency constraints/BOM overrides in our own build, but this has to be repeated by every
consumer of google-cloud-storage and does not fix the issue at the source.

Additional context

  • Affected artifact: com.google.cloud:google-cloud-storage, version 2.75.0
  • Transitive dependency: com.fasterxml.jackson.core:jackson-databind:2.18.3
  • Known vulnerabilities in jackson-databind 2.18.3:
    • Insecure deserialization issue, fixed in 2.18.8 / 2.21.4 / 3.1.4
    • DNS query vulnerability via InetSocketAddress, fixed in 2.18.8 / 2.21.4 / 3.1.4
    • Case-insensitive binding that reopens fields marked with @JsonIgnore, fixed in 2.18.9 / 2.21.5 / 3.1.4
  • Build tool: Maven/Gradle

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions