# Liquibase 4.14 security vulnerabilities

**URL:** https://forum.liquibase.org/t/liquibase-4-14-security-vulnerabilities/7115
**Category:** General Discussion
**Created:** [July 27, 2022, 1:26pm UTC](https://forum.liquibase.org/t/liquibase-4-14-security-vulnerabilities/7115 "2022-07-27T13:26:10Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![dishantj](https://avatars.discourse-cdn.com/v4/letter/d/ce73a5/32.png) [@dishantj](https://forum.liquibase.org/u/dishantj)
#### Post date: [July 27, 2022, 1:26pm UTC](https://forum.liquibase.org/t/liquibase-4-14-security-vulnerabilities/7115/1 "2022-07-27T13:26:10Z")

</div>

We ran vulnerabilty scan on our application that uses liquibase and a total of 80 critical(30) and high (50) rated CSVV3 vulnerabilities were detected.

The following components were detected as outdated and vulnerable:

- jackson-databind
- sqlite3 3.23.1
- tika
- httpcomponents-client

Below are the identified vulnerabilities

 ![vulnerabilities](https://us1.discourse-cdn.com/flex020/uploads/liquibase1/original/1X/2ffcd15499ba18ef30afe938c947d0f949c08689.png)

More details can be found at [NVD - Vulnerabilities](https://nvd.nist.gov/vuln)

Could someone help shed some light on when these components might get upgraded?

Thanks,  
Dishant

---

<div class="post-metadata">

### Author: ![ktaggart](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/ktaggart/32/596_2.png) [@ktaggart](https://forum.liquibase.org/u/ktaggart)
#### Post date: [July 27, 2022, 5:51pm UTC](https://forum.liquibase.org/t/liquibase-4-14-security-vulnerabilities/7115/2 "2022-07-27T17:51:21Z")

</div>

Please follow our SECURITY.md found here:

> <https://github.com/liquibase/liquibase/blob/master/SECURITY.md>

We will need to understand a few more details, as we also scan on our end before we release and do not release with critical nor high CVEs in the liquibase code.

Thanks,  
KT

---

<div class="post-metadata">

### Author: ![ktaggart](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/ktaggart/32/596_2.png) [@ktaggart](https://forum.liquibase.org/u/ktaggart)
#### Post date: [July 27, 2022, 5:54pm UTC](https://forum.liquibase.org/t/liquibase-4-14-security-vulnerabilities/7115/3 "2022-07-27T17:54:25Z")

</div>


