MGASA-2024-0069

Advisory lineage Upstream: 3 Downstream: 0
Published: 16 Mar 2024, 16:28
Last modified:16 Apr 2026, 04:22

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Mar 2024, 16:28
Published
Vulnerability first disclosed
16 Apr 2026, 04:22
Last Modified
Vulnerability information updated

Description

Updated jackson-databind packages fix security vulnerabilities jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. (CVE-2022-42003) In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. (CVE-2022-42004)

Affected Systems

  • mageiajackson-databind

    < 2.11.4-2.1.mga9

References (10)