viesti / timbre-json-appender

JSON appender for Timbre
MIT License
44 stars 11 forks source link

Bump jsonista due to CVE-2020-36518 #27

Closed gilch closed 2 years ago

gilch commented 2 years ago

jsonista dependency jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. https://nvd.nist.gov/vuln/detail/CVE-2020-36518

viesti commented 2 years ago

Thanks!