Package
sonarqube
Component
jackson-databind
Latest update
Fixed version
26.8.0.126808-r0
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
26.8.0.126808-r0Status
Impact
Vulnerable jackson is shaded into pre-built third-party jars: sonar-scanner-engine-community 13.1.3.3768 at 2.21.3, sonar-python-plugin 5.24.0.34324 at 2.21.0, sonar-text-plugin 2.45.0.11557 at 2.21.2, plus Elasticsearch's elasticsearch-x-content at 2.17.2 and x-pack-inference jackson-core 2.15.0. A Gradle dependency bump cannot rewrite shaded copies, and sonarqube 26.7.0.124771 is the latest upstream release. Blocked on new SonarSource plugin and Elasticsearch releases.
Status