CVE-2020-36518: High severity fasterxml jackson-databind vulnerability
A flaw was found in the Jackson Databind package. This cause of the issue is due to a Java StackOverflow exception and a denial of service via a significant depth of nested objects.
Other sources
A Java StackOverflow exception and denial of service via a large depth of nested objects.
Reference:
https://github.com/FasterXML/jackson-databind/issues/2816
— Red Hat
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8-3+deb10u5Fixed in 2.12.1-1+deb11u1Fixed in 2.14.0-1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 0:2.14.1-2.el9 - Upgrade
Upgrade
redhat/eap7-jackson-databindto a version that resolves this vulnerability.Fixed in 0:2.12.6.1-1.redhat_00003.1.el8ea - Upgrade
Upgrade
redhat/eap7-jackson-databindto a version that resolves this vulnerability.Fixed in 0:2.12.6.1-1.redhat_00003.1.el7ea - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:15.0.8-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:15.0.8-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7to a version that resolves this vulnerability.Fixed in 0:1-5.el9 - Upgrade
Upgrade
redhat/rh-sso7-javapackages-toolsto a version that resolves this vulnerability.Fixed in 0:6.0.0-7.el9 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el9 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.12.6.1 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.13.2.1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.12.6.1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.13.2.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:7435
- RHSA-2022:8889
- RHSA-2022:5101
- RHSA-2022:5596
- RHSA-2022:2232
- RHSA-2023:2312
- RHSA-2022:6407
- RHSA-2022:6819
- RHSA-2023:3223
- RHSA-2022:4922
- RHSA-2022:4919
- RHSA-2022:4918
- RHSA-2022:5532
- RHSA-2022:6813
- RHSA-2022:6787
- RHSA-2022:7417
- RHSA-2022:6782
- RHSA-2022:6783
- RHSA-2022:7409
- RHSA-2022:7410
- RHSA-2022:7411
- RHSA-2022:8781
- RHSA-2023:0264
- RHSA-2022:5029
- IBM-7262513
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36518.
What is the severity level of CVE-2020-36518?
CVE-2020-36518 has a severity level of high (7).
How does CVE-2020-36518 cause a denial of service?
CVE-2020-36518 causes a denial of service by exploiting a Java StackOverflow exception through the use of a large depth of nested objects.
Which software versions are affected by CVE-2020-36518?
Versions of jackson-databind before 2.13.0 are affected by CVE-2020-36518.
How can I fix CVE-2020-36518?
To fix CVE-2020-36518, update jackson-databind to version 2.13.0 or newer.