The JRJC uses Jackson 1.9 which is vulnerable due to CVE-2019-10172 and has no patched version of Jackson 1.9 to upgrade to. Any way to mitigate this? Any plans to upgrade to Jackson 2.x
Hi!
one of the option make a fork and do changes and make a PR,
https://bitbucket.org/atlassian/jira-rest-java-client/src/master/
Cheers,
Gonchik
It looks like you're new here. Sign in or register to get started.