Skip to content

fix(security): upgrade Jackson to 2.21.7 for TFS bug 712007 - #90

Open
dev-bot-laserfiche wants to merge 1 commit into
2.xfrom
devbot/veracode/sca-app-1791234-comp-5bc97c69-5880-48b2-aead-85df2b6ee5dd
Open

dev-bot-laserfiche wants to merge 1 commit into
2.xfrom
devbot/veracode/sca-app-1791234-comp-5bc97c69-5880-48b2-aead-85df2b6ee5dd

Conversation

@dev-bot-laserfiche

Copy link
Copy Markdown

Description of changes: Remediates CVE-2026-91776 tracked by TFS bug 712007 by raising the shared Jackson version from 2.21.6 to 2.21.7, the latest Maven Central patch in this repository's existing 2.21 LTS line. This updates jackson-databind and jackson-core together; jackson-annotations stays at its existing independently versioned 2.21 release.

The dependency is used directly by the library's JSON mappers and custom deserializers, so removing it is not appropriate. Although the built-in token models do not enable name-based polymorphic fallback, the public TokenClientObjectMapper.readValue(String, Class) API accepts caller-defined annotated models. A regression using that public API reproduced the finding on 2.21.6: 10,000 distinct unknown IDs retained 10,001 cache entries including a known subtype, while 10,000 repetitions of one unknown ID retained one entry.

The new regression passes on 2.21.7 and checks the cache never exceeds 1,000 entries in the sequential workload, fallback values remain correct, known subtypes still deserialize after cache churn, repeated IDs retain one entry, and overlong IDs are not retained. The changelog records the security patch. No lockfile exists in this Maven repository.

Verification used Java 8 and Maven 3.9.11:

  • mvn -B '-Dtest=com.laserfiche.api.client.unit.*Test,!com.laserfiche.api.client.unit.OAuthClientCredentialsHandlerTest,!com.laserfiche.api.client.unit.TokenClientUtilsTest' package succeeded: 44 tests, zero failures or errors, one existing skipped test; packaging and attached Javadoc/source/test jars also succeeded.
  • mvn -B dependency:tree -Dincludes=com.fasterxml.jackson.core:* resolved jackson-databind and jackson-core exclusively to 2.21.7, with jackson-annotations 2.21.
  • The complete local unit selector was attempted before changing the dependency. OAuthClientCredentialsHandlerTest and TokenClientUtilsTest failed in their existing BaseTest setup because integration credentials were unavailable; these two classes were excluded from the passing local command. Live integration tests were not run locally.
  • The regression was run on 2.21.6 first: the distinct-ID cache bound and overlong-ID assertions failed, and the repeated-ID control passed.

After human review and merge, rebuild/publish the library and run the next Veracode scan to clear the scanned component finding. This PR does not change publication configuration or the bug's state.

Work item links

Bound polymorphic fallback type-ID caching through the patched 2.21 LTS release and cover distinct, repeated, and overlong IDs through the public mapper API.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

unit-test-results

49 tests  +3   48 ✅ +3   2s ⏱️ -1s
 9 suites +1    1 💤 ±0 
 9 files   +1    0 ❌ ±0 

Results for commit c13d4b6. ± Comparison against base commit 05e0438.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

integration-test-results-cloud

14 tests  ±0   14 ✅ ±0   12s ⏱️ +2s
 2 suites ±0    0 💤 ±0 
 2 files   ±0    0 ❌ ±0 

Results for commit c13d4b6. ± Comparison against base commit 05e0438.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

integration-test-results-self-hosted

6 tests  ±0   6 ✅ ±0   7s ⏱️ +6s
1 suites ±0   0 💤 ±0 
1 files   ±0   0 ❌ ±0 

Results for commit c13d4b6. ± Comparison against base commit 05e0438.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant