Jira Rest Java Client - JRJC - CVE-2019-10172

Anthony Lee January 4, 2022

The JRJC uses Jackson 1.9 which is vulnerable due to CVE-2019-10172 and has no patched version of Jackson 1.9 to upgrade to. Any way to mitigate this? Any plans to upgrade to Jackson 2.x

1 answer

0 votes
Gonchik Tsymzhitov
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
January 4, 2022

Hi! 

one of the option make a fork and do changes and make a PR,

https://bitbucket.org/atlassian/jira-rest-java-client/src/master/

 

Cheers,

Gonchik 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events