CVE-2020-36518 : Unable to resolve WhiteSource vulnerability for jackson-databind library

Viewed 952

I have tried all the versions of jackson-databind (including version suggested on whitesource fix), but all the version for jackson-databind showing vulnerability on whitesource scan.

Below is the description of the issue and we can also see the WhiteSource Note : enter image description here

Can someone help me here to resolve this?

Note: I am using jackson-databind dependency so can not exclude it in pom.xml

1 Answers
Related