Skip to content

update jackson-databind to fix CVE-2020-36518 #567

@zz-jason

Description

@zz-jason

Bug Report

1. Describe the bug

jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects. There is currently no workaround but a patch will be available in version 2.14.

CVE ID: CVE-2020-36518

2. Minimal reproduce step (Required)

N/A

3. What did you see instead (Required)

Screen Shot 2022-03-24 at 14 14 13

4. What did you expect to see? (Required)

5. What is your Java Client and TiKV version? (Required)

  • Client Java: latest(commit hash: 92fea32)
  • TiKV: N/A

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions