Upgrade Jackson Databind dependency to fix deserialization vulnerability CVE-2017-7525. The plugins are currently using com.fasterxml.jackson.core:jackson-databind:2.5.3. It needs to be upgraded to one of these versions 2.6.7.1, 2.7.9.1, 2.8.9, 2.9.0
Reference FasterXML/jackson-databind#1723