openfire-monitoring-plugin icon indicating copy to clipboard operation
openfire-monitoring-plugin copied to clipboard

CVE-2020-36518: jackson-databind security issue

Open jackiedlh opened this issue 2 years ago • 1 comments

https://nvd.nist.gov/vuln/detail/CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

jackiedlh avatar Jul 22 '22 07:07 jackiedlh

@guusdk, @Flowdalic: Have you seen this CVE issue?

There is a PR here:

  • https://github.com/igniterealtime/openfire-monitoring-plugin/pull/231

Neustradamus avatar Feb 24 '23 13:02 Neustradamus