Skip to content

Fix CVE-2020-36518 #8

@elenigen

Description

@elenigen

https://github.expedia.biz/advisories/GHSA-57j2-w4cx-62h2
high severity
Vulnerable versions: <= 2.12.6.0
Patched version: 2.12.6.1
jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions