CVE-2020-36518
Summary
| CVE | CVE-2020-36518 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-11 07:15:00 UTC |
| Updated | 2022-11-29 22:12:00 UTC |
| Description | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| CVE-2020-36518 FasterXML Jackson Databind Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] [DLA 2990-1] jackson-databind security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-5283-1 jackson-databind | DEBIAN | www.debian.org | |
| Optimize `UntypedObjectDeserializer` wrt recursion · Issue #2816 · FasterXML/jackson-databind · GitHub | MISC | github.com | |
| [SECURITY] [DLA 3207-1] jackson-databind security update | MLIST | lists.debian.org | |
| Oracle Critical Patch Update Advisory - July 2022 | N/A | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160620 Oracle Enterprise Linux Security Update for jackson (ELSA-2023-2312)
- 179257 Debian Security Update for jackson-databind (DLA 2990-1)
- 181229 Debian Security Update for jackson-databind (DSA 5283-1)
- 181250 Debian Security Update for jackson-databind (DLA 3207-1)
- 20270 Oracle Database 21c Critical Patch Update - October 2022
- 20271 Oracle Database 19c Critical Patch Update - October 2022
- 20272 Oracle Database 19c Critical OJVM Patch Update - October 2022
- 240458 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 7 (RHSA-2022:4918)
- 240459 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 8 (RHSA-2022:4919)
- 241418 Red Hat Update for jackson (RHSA-2023:2312)
- 376735 Oracle Coherence July 2022 Critical Patch Update (CPUJUL2022)
- 378990 Atlassian Jira Service Management Data Center and Server Denial of Service (DoS) Vulnerability (JSDSERVER-14749,JSDSERVER-14751,JSDSERVER-14752,JSDSERVER-14753,JSDSERVER-14754,JSDSERVER-14755)
- 379113 Splunk Enterprise Third Party Package Updates for November (SVD-2022-1113)
- 379561 Atlassian Bitbucket Data Center and Server jackson-databind Dependency Vulnerability (BSERV-18830)
- 691048 Free Berkeley Software Distribution (FreeBSD) Security Update for kafka (01823528-a4c1-11ed-b6af-b42e991fc52e)
- 752129 SUSE Enterprise Linux Security Update for jackson-databind, jackson-dataformats-binary, jackson-annotations, jackson-bom, jackson-core (SUSE-SU-2022:1678-1)
- 87496 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2022)
- 941033 AlmaLinux Security Update for jackson (ALSA-2023:2312)