Skip to content

Conversation

@hangc0276
Copy link
Contributor

Motivation

Fix CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Modification

Upgrade jackson version from 2.11.0 to 2.13.2

@dlg99
Copy link
Contributor

dlg99 commented Mar 24, 2022

FYI I covered this in #3130 (for gradle and maven).

@nicoloboschi
Copy link
Contributor

This will not fix the CVE-2020-36518, there's no safe release yet

FasterXML/jackson-databind#2816

@hangc0276
Copy link
Contributor Author

Another PR fix it. #3140. Close this one.

@hangc0276 hangc0276 closed this Mar 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants