CVE-2020-28491
Last modified
CVE-2020-28491 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.. EPSS estimates a 3.07% chance of exploitation in the next 30 days.
Description
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Dataformats-Binary | < 2.11.4 |
| Fasterxml | Jackson-Dataformats-Binary | > 2.12.0, < 2.12.1 |
| Fasterxml | Jackson-Dataformats-Binary | 2.12.0 |
| Quarkus | Quarkus | < 2.0.2 |
| Oracle | Weblogic Server | 12.2.1.3.0 |
| Oracle | Weblogic Server | 12.2.1.4.0 |
| Oracle | Weblogic Server | 14.1.1.0.0 |
References
- https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6Patch, Third Party Advisory
- https://github.com/FasterXML/jackson-dataformats-binary/issues/186Issue Tracking, Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6Patch, Third Party Advisory
- https://github.com/FasterXML/jackson-dataformats-binary/issues/186Issue Tracking, Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-28491?
How severe is CVE-2020-28491?
How do I fix CVE-2020-28491?
Are you affected by CVE-2020-28491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
