Description
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.
Remediation
References
https://hackerone.com/reports/315037
Related Vulnerabilities
CVE-2019-16560 Vulnerability in maven package org.jenkins-ci.plugins:websphere-deployer
CVE-2018-18628 Vulnerability in maven package ro.pippo:pippo-session
CVE-2020-1950 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2018-1000129 Vulnerability in maven package org.jolokia:jolokia-core