Jason Ryan
09/02/2022, 6:18 PMcom.fasterxml.jackson.core:jackson-databind
from the Lucee docker images? I tried out the light build, which unlike the normal build appears to not include this in /opt/lucee/server/lucee-server/bundle
but my ECR image scan is still flagging numerous critical vulnerabilites coming from that package (like 30+)
Edit: Was able to determine this comes from Commandbox (root/.CommandBox/engine/cfml/cli/lucee-server/bundles/org.lucee.ehcache-2.10.3.jar
)bdw429s
09/02/2022, 9:38 PMbdw429s
09/02/2022, 9:38 PMbdw429s
09/02/2022, 9:38 PMbdw429s
09/02/2022, 9:38 PMbdw429s
09/02/2022, 9:39 PMJason Ryan
09/02/2022, 9:40 PMJason Ryan
09/02/2022, 9:40 PMbdw429s
09/02/2022, 9:41 PMbdw429s
09/02/2022, 9:42 PMseancorfield
seancorfield