Issues
- mod-finc-config: Isil API allows invalid valuesUIFC-426Tino R.
- ui-plugin-find-finc-metadata-source: Release v8.0.0UIFC-425Resolved issue: UIFC-425Tino R.
- ui-plugin-find-finc-metadata-collection: Release v7.0.0UIFC-424Resolved issue: UIFC-424Tino R.
- ui-finc-select: Release v8.0.0UIFC-423Resolved issue: UIFC-423Tino R.
- ui-finc-config: Release v8.0.0UIFC-422Resolved issue: UIFC-422Tino R.
- mod-finc-config: Release v6.1.0UIFC-421Resolved issue: UIFC-421Tino R.
- mod-finc-config: Update to Java 21UIFC-420Resolved issue: UIFC-420Tino R.
- ui-plugin-find-finc-metadata-collection: migrate react-intl to v7UIFC-417Resolved issue: UIFC-417Viola E.
- ui-plugin-find-finc-metadata-collection: migrate stripes dependencies to their Sunflower versionsUIFC-416Resolved issue: UIFC-416Viola E.
- ui-plugin-find-finc-metadata-source: migrate react-intl to v7UIFC-415Resolved issue: UIFC-415Viola E.
- ui-plugin-find-finc-metadata-source: migrate stripes dependencies to their Sunflower versionsUIFC-414Resolved issue: UIFC-414Viola E.
- ui-finc-select: migrate react-intl to v7UIFC-413Resolved issue: UIFC-413Viola E.
- ui-finc-select: migrate stripes dependencies to their Sunflower versionsUIFC-412Resolved issue: UIFC-412Viola E.
- ui-finc-config: migrate stripes dependencies to their Sunflower versionsUIFC-411Resolved issue: UIFC-411Viola E.
- ui-finc-config: migrate react-intl to v7UIFC-410Resolved issue: UIFC-410Viola E.
- mod-finc-config: Utilize timer interface instead of QuartzUIFC-409
- mod-finc-config: Compare ezb files by checksumUIFC-408
- mod-finc-config: No random port used when deploying RestVerticle in testsUIFC-407Resolved issue: UIFC-407Tino R.
- mod-finc-config: Increase maximum allowed string length in Jacksons ObjectMapperUIFC-406Resolved issue: UIFC-406Tino R.
- mod-finc-config: Upload of large files failsUIFC-405
- mod-finc-config: Provide filter file path in API endpoint /metadata-collectionsUIFC-404Tino R.
- ui-finc-select: adapt index.test.js and add route testsUIFC-403Resolved issue: UIFC-403Viola E.
- ui-finc-config: adapt index.test.js and route testsUIFC-402Resolved issue: UIFC-402Viola E.
- ui-finc-config: Restructure of testing, add tests for SASQUIFC-401Resolved issue: UIFC-401Viola E.
- ui-finc-config: Restructure SASQ and localStorageUIFC-400Resolved issue: UIFC-400Viola E.
- ui-finc-select: Restructure of testing, add tests for SASQUIFC-399Resolved issue: UIFC-399Viola E.
- mod-finc-config: URL for download of EZB files should be configurableUIFC-398Resolved issue: UIFC-398Tino R.
- mod-finc-config: Release v6.0.0UIFC-397Resolved issue: UIFC-397Tino R.
- ui-finc-config: add rules for eslint, add config file for prettierUIFC-396Resolved issue: UIFC-396Viola E.
- ui-finc-select: Update permissionsUIFC-395Resolved issue: UIFC-395Tino R.
- ui-finc-config: Update permissionsUIFC-394Resolved issue: UIFC-394Tino R.
- mod-finc-config: Remove unimplemented endpointsUIFC-393Resolved issue: UIFC-393Tino R.
- mod-finc-config: Review and cleanup Module DescriptorUIFC-392Resolved issue: UIFC-392Tino R.
- ui-plugin-find-finc-metadata-collection: Release v7.0.0UIFC-391Resolved issue: UIFC-391Viola E.
- ui-plugin-find-finc-metadata-source: Release v7.0.0UIFC-390Resolved issue: UIFC-390Viola E.
- ui-finc-select: Release v7.0.0UIFC-389Resolved issue: UIFC-389Viola E.
- ui-finc-config: Release v7.0.0UIFC-388Resolved issue: UIFC-388Viola E.
- ui-finc-select: Update required interfacesUIFC-387Resolved issue: UIFC-387Tino R.
- ui-plugin-find-finc-metadata-collection: Update required interfacesUIFC-386Resolved issue: UIFC-386Tino R.
- ui-plugin-find-finc-metadata-source: Update required interfacesUIFC-385Resolved issue: UIFC-385Tino R.
- ui-finc-config: Update required interfacesUIFC-384Resolved issue: UIFC-384Tino R.
- mod-finc-config: Update interface names per folio naming conventionUIFC-383Resolved issue: UIFC-383Tino R.
- mod-finc-config: Upgrade RMB to v35.3.0UIFC-382Resolved issue: UIFC-382Tino R.
- ui-finc-config: Refine EditCardUIFC-381Resolved issue: UIFC-381Viola E.
- ui-finc-select: Fix tests and add mocks localUIFC-379Resolved issue: UIFC-379Viola E.
- ui-finc-config: Fix tests and add mocks localUIFC-378Resolved issue: UIFC-378Viola E.
- ui-finc-select: Fix handleNeedMoreData in FiltersRouteUIFC-377Resolved issue: UIFC-377Viola E.
- finc-select: File download fails for large filesUIFC-376
- ui-finc-config: Fix update resources bug for MetadataSources and MetadataCollectionsUIFC-375Resolved issue: UIFC-375Viola E.
- ui-finc-select: Replace mutator and manifest with useOkapiKyUIFC-374Viola E.
50 of 405
Fix security vulnerabilities reported in jackson-databind >= 2.0.0, < 2.9.9.2
Done
Description
CSP Request Details
None
CSP Rejection Details
None
Potential Workaround
None
Checklist
hideTestRail: Results
Details
Details
Assignee
Hongwei Ji
Hongwei JiReporter
Peter Murray
Peter MurrayLabels
Priority
Story Points
0.5
Sprint
None
Development Team
Core: Platform
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created August 1, 2019 at 7:34 PM
Updated August 12, 2019 at 1:06 PM
Resolved August 2, 2019 at 4:16 PM
Activity
Show:
Hongwei Ji August 2, 2019 at 4:16 PM
Oops, I fixed it yesterday before seeing this ticket today.
Julian Ladisch August 2, 2019 at 4:13 PM
Hongwei Ji has merged the jackson-databind version bump to 2.9.9.2 to master:
https://github.com/folio-org/mod-login-saml/pull/48
We need a release of mod-login-saml if we want to deploy the fixed version.
Peter Murray August 1, 2019 at 7:36 PM
: Would you mind bumping the version here again?
Another day, another jackson-databind vulnerability?
2 com.fasterxml.jackson.core:jackson-databind vulnerabilities found in pom.xm 5 minutes ago
Remediation
Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.9.9.2 or later. For example:
Always verify the validity and compatibility of suggestions with your codebase.
Details
CVE-2019-14379
moderate severity
*Vulnerable versions:* < 2.9.9.2
*Patched version:* 2.9.9.2
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used, leading to remote code execution.
CVE-2019-14439
moderate severity
*Vulnerable versions:* < 2.9.9.2
*Patched version:* 2.9.9.2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.