Jackson Databind Vulnerability CVE-2020-36518
Issue date: 29-06-2022Affects versions: 15.0, 14.7, 13.4
Security Issue ID
SECURITY-307
Affected Product Version(s)
15.0.0, 14.7.6, 13.4.17, and all previous versions
Severity
medium
Description
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
This primarily affects REST endpoints built using the development frameworks provided by the brXM product. Since these endpoints may or may not include authentication depending on customer-specific implementation choices, we consider this a moderate risk.
Instructions
Update to the latest version.