Camunda-spin-datafromat and Jackson-databind vulnerability issue

Hello @Lakshan ,

you could try using camunda-spin-dataformat-jackson-json which does not shade but include jackson-databind as dependency.

Then, you could manage the dependency version if the version used in 7.18.0 camunda version is vulnerable and a patch exists for jackson-databind.

Jonathan

1 Like