MINOR: Update jackson databind to 2.10.5.1 (#9702)

Fixes:
* DOMDeserializer: setExpandEntityReferences(false) may not prevent external entity
expansion in all cases (CVE-2020-25649)

Full details: https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.10#micro-patches

Reviewers: Ismael Juma <ismael@juma.me.uk>
This commit is contained in:
Julien Jean Paul Sirocchi 2020-12-16 00:26:59 +00:00 committed by GitHub
parent a084dd829c
commit f285188f10
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 1 deletions

View File

@ -67,6 +67,7 @@ versions += [
httpclient: "4.5.12",
easymock: "4.2",
jackson: "2.10.5",
jacksonDatabind: "2.10.5.1",
jacoco: "0.8.5",
jetty: "9.4.33.v20201020",
jersey: "2.31",
@ -134,7 +135,7 @@ libs += [
commonsCli: "commons-cli:commons-cli:$versions.commonsCli",
easymock: "org.easymock:easymock:$versions.easymock",
jacksonAnnotations: "com.fasterxml.jackson.core:jackson-annotations:$versions.jackson",
jacksonDatabind: "com.fasterxml.jackson.core:jackson-databind:$versions.jackson",
jacksonDatabind: "com.fasterxml.jackson.core:jackson-databind:$versions.jacksonDatabind",
jacksonDataformatCsv: "com.fasterxml.jackson.dataformat:jackson-dataformat-csv:$versions.jackson",
jacksonModuleScala: "com.fasterxml.jackson.module:jackson-module-scala_$versions.baseScala:$versions.jackson",
jacksonJDK8Datatypes: "com.fasterxml.jackson.datatype:jackson-datatype-jdk8:$versions.jackson",