Done
Details
Assignee
UnassignedUnassignedReporter
DenisDenisPriority
TBDRCA Group
TBDTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Unassigned
UnassignedReporter
Denis
DenisPriority
RCA Group
TBD
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created April 18, 2024 at 1:09 PM
Updated May 23, 2024 at 3:51 PM
Resolved May 23, 2024 at 3:51 PM
Similar CVE was reporter in January 2024 https://folio-org.atlassian.net/browse/SECURITY-14 Now it deals with new modules.
Severity: High
Link: https://github.com/FasterXML/jackson-core/pull/827
Package Name: com.fasterxml.jackson.core_jackson-core
Current version 2.13.5 // fixed in 2.15.0
Modules impacted:
mod-licenses 6.0.0
mod-event-config 2.7.0 – https://folio-org.atlassian.net/browse/MODEVENTC-53 – fixed in 2.7.1
mod-invoice-storage 5.8.0 – https://folio-org.atlassian.net/browse/MODINVOSTO-181 – fixed for Ramsons
mod-service-interaction 4.0.1
mod-agreements 7.0.0
mod-audit 2.9.0 – https://folio-org.atlassian.net/browse/MODAUD-185 – fixed for Ramsons
mod-serials-management 1.0.0
mod-invoice 5.8.1 – https://folio-org.atlassian.net/browse/MODINVOICE-545 – fixed for Ramsons