igniterealtime/openfire-monitoring-plugin

CVE-2020-36518: jackson-databind security issue

jackiedlh opened this issue · 1 comments

https://nvd.nist.gov/vuln/detail/CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

@guusdk, @Flowdalic: Have you seen this CVE issue?

There is a PR here: