-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Jackson Release 2.13.5
Tatu Saloranta edited this page Nov 13, 2022
·
7 revisions
Possible patch version of 2.13, not yet released.
Following fixes would be included in this patch release.
-
#3590: Add check in primitive value deserializers to avoid deep wrapper array nesting wrt
UNWRAP_SINGLE_VALUE_ARRAYS[CVE-2022-42003] - #3659: Improve testing (likely via CI) to try to ensure compatibility with specific Android SDKs
- #3661: Jackson 2.13 uses Class.getTypeName() that is only available on Android SDK 26
- Upgrade Woodstox to 6.4.0 for a fix to [CVE-2022-40152]
-
#98:
module-info.javaofjr-streerefers to modulecom.fasterxml.jackson.jr.ob.api, which is not defined