Skip to content

CVE-2020-28491 @ Maven-com.fasterxml.jackson.dataformat:jackson-dataformat-cbor-2.6.7 #115

@scott-cx

Description

@scott-cx

Vulnerable Package issue exists @ Maven-com.fasterxml.jackson.dataformat:jackson-dataformat-cbor-2.6.7 in branch main

This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

Namespace: scott-cx
Repository: edgemere
Repository Url: https://github.com/scott-cx/edgemere
CxAST-Project: scott-cx/edgemere
CxAST platform scan: 45abb8d9-377e-427c-92f9-26a15742bad7
Branch: main
Application: edgemere
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-770


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 2.11.4


References
Advisory
Issue
Commit

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions