CVE-2020-36518

NameCVE-2020-36518
Descriptionjackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2990-1, DLA-3207-1, DSA-5283-1
Debian Bugs1007109

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jackson-databind (PTS)buster2.9.8-3+deb10u3vulnerable
buster (security)2.9.8-3+deb10u5fixed
bullseye (security), bullseye2.12.1-1+deb11u1fixed
sid, trixie, bookworm2.14.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jackson-databindsourcestretch2.8.6-1+deb9u10DLA-2990-1
jackson-databindsourcebuster2.9.8-3+deb10u4DLA-3207-1
jackson-databindsourcebullseye2.12.1-1+deb11u1DSA-5283-1
jackson-databindsource(unstable)2.13.2.2-11007109

Notes

https://github.com/FasterXML/jackson-databind/issues/2816

Search for package or bug name: Reporting problems