Skip to content

[CVE-2020-36518] Update jackson-databind to 2.13.2.1 #2597

@reta

Description

@reta

Describe the bug

jackson-databind up to 2.13.2 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

[1] https://nvd.nist.gov/vuln/detail/CVE-2020-36518
[2] FasterXML/jackson-databind#2816

To Reproduce
Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Expected behavior
Update jackson-databind to 2.13.2.1

Plugins
Please list all plugins currently enabled.

Screenshots
If applicable, add screenshots to help explain your problem.

Host/Environment (please complete the following information):

  • OS: [e.g. iOS]
  • Version [e.g. 22]

Additional context
Add any other context about the problem here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions