Jackson Databind Vulnerability CVE-2020-36518 

Issue date: 29-06-2022
Affects versions: 15.0, 14.7, 13.4

Security Issue ID

SECURITY-307

 

Affected Product Version(s)

15.0.0, 14.7.6, 13.4.17, and all previous versions


Severity 

medium


Description

CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

This primarily affects REST endpoints built using the development frameworks provided by the brXM product. Since these endpoints may or may not include authentication depending on customer-specific implementation choices, we consider this a moderate risk.

Instructions

Update to the latest version.