Package | jackson-databind |
---|---|
Version | 2.4.2-2+deb8u17 |
Related CVEs | CVE-2020-36518 |
It was discovered that the implementation of UntypedObjectDeserializer in jackson-databind, a fast and powerful JSON library for Java, was prone to a denial of service attack when deeply nested object and array values were processed.
For Debian 8 jessie, these problems have been fixed in version 2.4.2-2+deb8u17.
We recommend that you upgrade your jackson-databind packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.