CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*

Information

Published : 2022-03-11 07:15

Updated : 2022-07-25 18:15


NVD link : CVE-2020-36518

Mitre link : CVE-2020-36518


JSON object : View

Products Affected

fasterxml

  • jackson-databind

oracle

  • communications_cloud_native_core_console
CWE
CWE-787

Out-of-bounds Write