Revision Date: | 2021-01-29 | Version: | 1 |
Title: | (Moderate) |
Description: |
This update for jackson-databind fixes the following issues:
jackson-databind was updated to 2.10.5.1: * #2589: `DOMDeserializer`: setExpandEntityReferences(false) may not prevent external entity expansion in all cases (CVE-2020-25649, bsc#1177616) * #2787 (partial fix): NPE after add mixin for enum * #2679: 'ObjectMapper.readValue('123', Void.TYPE)' throws 'should never occur'
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1177616 1180391 1181118 CVE-2017-12852 CVE-2019-6446 CVE-2020-25649 CVE-2020-35728 CVE-2021-20190
|
Platform(s): | Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE SUSE Linux Enterprise Desktop 15 SP2 SUSE Linux Enterprise High Performance Computing 15 SP2 SUSE Linux Enterprise Module for Basesystem 15 SP2 SUSE Linux Enterprise Server 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.1 SUSE Manager Server 4.1
| Product(s): | |
Definition Synopsis |
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE is installed AND jackson-databind-2.10.5.1-3.3.2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
AND Package Information
python3-numpy-1.17.3-4.11.1 is installed
OR python3-numpy-devel-1.17.3-4.11.1 is installed
|