Skip to content

[RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) - #67

Open
fdevans wants to merge 1 commit into
mainfrom
security/CVE-2026-19032-jackson
Open

[RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032)#67
fdevans wants to merge 1 commit into
mainfrom
security/CVE-2026-19032-jackson

Conversation

@fdevans

@fdevans fdevans commented Sep 8, 2026

Copy link
Copy Markdown

What

Bumps rundeck-core from 6.1.0-20260803 to 6.2.0-20260908.

Why

CVE-2026-19032: 6.1.0-20260803 pulls in a vulnerable transitive
Jackson version. 6.2.0-20260908 includes the fix.

Note

6.2.0-20260908 was published today. If the CI build here fails to
resolve it, that's expected propagation lag on the Sonatype snapshots
feed, not a real problem with this change - rerun the build once it's
synced.

rundeck-core 6.1.0-20260803 pulls in a vulnerable transitive Jackson
version (CVE-2026-19032). 6.2.0-20260908 includes the fix.
@fdevans
fdevans requested review from a team and a lite review from Copilot September 8, 2026 22:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@fdevans fdevans changed the title Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) [RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants