All vulnerabilities

CVE-2020-36518

Deeply nested json in jackson-databind

Description

jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
Java
Publish Date
March 11, 2022
Modified Date
October 22, 2024
Score Vector
Affected Versions