minor
defect
Currently, version 2.13.2 of the Jackson FasterXML library is in use.
This version contains a security vulnerability:
In FasterXML jackson-databind versions prior to 2.13.4, resource exhaustion can occur because of a missing check in `BeanDeserializer._deserializeFromArray` to prevent the use of deeply nested arrays. An application is vulnerable only under certain customized deserialization settings.
More information here.
Test
The CheckDependencies build task should not contain any errors of the type “com.top-logic:tl-parent-all.pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.2.2.”