A flaw was discovered in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data.
Please note that related and complementary jackson-* packages like jackson- databind or jackson-dataformat-smile had to be upgraded as well in order to fix build failures caused by the changes to jackson-core.
https://security-tracker.debian.org/tracker/DSA-6336-1
Continue reading...
Please note that related and complementary jackson-* packages like jackson- databind or jackson-dataformat-smile had to be upgraded as well in order to fix build failures caused by the changes to jackson-core.
https://security-tracker.debian.org/tracker/DSA-6336-1
Continue reading...

