Root has patched CVE-2019-10172 in the io.root.org.codehaus.jackson:jackson-mapper-asl package for Root:Maven. Multiple fixed versions available.
{ "distro": "maven", "source": "Root", "distro_version": "", "severity": "HIGH" }
"root.io.3"
3.0
"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2019-10172.json"
"1.9.13"
true
[ "1.9.13-root.io.1", "1.9.13-root.io.2", "1.9.13-root.io.3" ]
""
1.0
"1.9.13-aikido.3"
[ "1.9.13-aikido.3" ]