sendgrid / sendgrid-java

The Official Twilio SendGrid Led, Community Driven Java API Library
https://sendgrid.com
MIT License
483 stars 408 forks source link

chore: security upgrade jackson-databind from 2.13.0 to 2.13.2 #726

Closed tomoyaY closed 2 years ago

tomoyaY commented 2 years ago

Changes included in this PR

ref

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

https://nvd.nist.gov/vuln/detail/CVE-2020-36518