upgrade jackson-databind and commons-beanutils for CVEs

Signed-off-by: Shen-Ta Hsieh <ibmibmibm.tw@gmail.com>
master
Shen-Ta Hsieh 5 years ago
parent 16c1e42b97
commit 394dfa1ce7
No known key found for this signature in database
GPG Key ID: DF7FED2B0492FA77
  1. 1
      airsonic-main/pom.xml
  2. 7
      pom.xml

@ -426,6 +426,7 @@
<dependency> <dependency>
<groupId>commons-beanutils</groupId> <groupId>commons-beanutils</groupId>
<artifactId>commons-beanutils</artifactId> <artifactId>commons-beanutils</artifactId>
<version>1.9.4</version>
<!-- commons-configuration2 requires during runtime --> <!-- commons-configuration2 requires during runtime -->
<scope>runtime</scope> <scope>runtime</scope>
</dependency> </dependency>

@ -17,7 +17,6 @@
<failOnDependencyWarning>true</failOnDependencyWarning> <failOnDependencyWarning>true</failOnDependencyWarning>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<cxf.version>3.3.1</cxf.version> <cxf.version>3.3.1</cxf.version>
<jackson.version>2.9.9</jackson.version>
<tomcat.version>8.5.42</tomcat.version> <tomcat.version>8.5.42</tomcat.version>
</properties> </properties>
@ -114,17 +113,17 @@
<dependency> <dependency>
<groupId>com.fasterxml.jackson.core</groupId> <groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-core</artifactId> <artifactId>jackson-core</artifactId>
<version>${jackson.version}</version> <version>2.9.9</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>com.fasterxml.jackson.core</groupId> <groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId> <artifactId>jackson-databind</artifactId>
<version>${jackson.version}</version> <version>2.9.9.3</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>com.fasterxml.jackson.core</groupId> <groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-annotations</artifactId> <artifactId>jackson-annotations</artifactId>
<version>${jackson.version}</version> <version>2.9.9</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>com.google.guava</groupId> <groupId>com.google.guava</groupId>

Loading…
Cancel
Save