-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 7.1 DXP (7.1.10)
-
Fix Version/s: 7.1.x EE
-
Component/s: Liferay Push, Security Vulnerability
-
Labels:None
-
7.1 Fix Pack Version:22
Liferay Push is bundled with Jackson Databind 2.10.3 which has known vulnerabilities. For more details, please see https://nvd.nist.gov/vuln/search/results?adv_search=true&query=cpe%3A2.3%3Aa%3Afasterxml%3Ajackson-databind%3A2.10.3%3A*%3A*%3A*%3A*%3A*%3A*%3A*
Fixed in Liferay Push 3.0.3.