Bug Description
Hello, we're seeing a dependency review failure due to the inclusion of com.fasterxml.jackson.core:jackson-core:2.20.1
The GHSA flagged is GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition.
The vulnerability concerns a malicious input causing a DoS, I doubt it is relevant to CycloneDx but is still flagged.
Any chance of updating to the fixed version 2.21.1?
Self-contained Reproducer Project
N/A
Expected Behavior
N/A
Gradle build scan URL (optional)
No response
OS
No response
Gradle version
No response
CycloneDX Plugin version
3.1.1
Additional Context
No response
Contribution
Bug Description
Hello, we're seeing a dependency review failure due to the inclusion of
com.fasterxml.jackson.core:jackson-core:2.20.1The GHSA flagged is GHSA-72hv-8253-57qq jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition.
The vulnerability concerns a malicious input causing a DoS, I doubt it is relevant to CycloneDx but is still flagged.
Any chance of updating to the fixed version 2.21.1?
Self-contained Reproducer Project
N/A
Expected Behavior
N/A
Gradle build scan URL (optional)
No response
OS
No response
Gradle version
No response
CycloneDX Plugin version
3.1.1
Additional Context
No response
Contribution