jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
References
| Link | Resource |
|---|---|
| https://github.com/FasterXML/jackson-databind/issues/2816 | Issue Tracking Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html | |
| https://security.netapp.com/advisory/ntap-20220506-0004/ | |
| https://www.oracle.com/security-alerts/cpujul2022.html |
Information
Published : 2022-03-11 07:15
Updated : 2022-07-25 18:15
NVD link : CVE-2020-36518
Mitre link : CVE-2020-36518
JSON object : View
Products Affected
fasterxml
- jackson-databind
oracle
- communications_cloud_native_core_console
CWE
CWE-787
Out-of-bounds Write
