First published: Thu Feb 18 2021(Updated: )
FasterXML jackson-dataformats-binary is vulnerable to a denial of service, caused by an unchecked allocation of byte buffer flaw. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a java.lang.OutOfMemoryError exception resulting in a denial of service condition.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
FasterXML jackson-dataformats-binary | <2.11.4 | |
FasterXML jackson-dataformats-binary | >2.12.0<2.12.1 | |
FasterXML jackson-dataformats-binary | =2.12.0 | |
FasterXML jackson-dataformats-binary | =2.12.0-rc1 | |
FasterXML jackson-dataformats-binary | =2.12.0-rc2 | |
Quarkus Quarkus | <2.0.2 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
redhat/jackson-dataformat-cbor | <2.11.4 | 2.11.4 |
redhat/jackson-dataformat-cbor | <2.12.1 | 2.12.1 |
redhat/rh-sso7-keycloak | <0:9.0.15-1.redhat_00002.1.el6 | 0:9.0.15-1.redhat_00002.1.el6 |
redhat/rh-sso7-keycloak | <0:9.0.15-1.redhat_00002.1.el7 | 0:9.0.15-1.redhat_00002.1.el7 |
redhat/rh-sso7-keycloak | <0:9.0.15-1.redhat_00002.1.el8 | 0:9.0.15-1.redhat_00002.1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-28491 is a vulnerability in the com.fasterxml.jackson.dataformat:jackson-dataformat-cbor package that allows for a denial of service attack.
CVE-2020-28491 has a severity rating of 7.5 (High).
The affected software for CVE-2020-28491 includes com.fasterxml.jackson.dataformat:jackson-dataformat-cbor versions 0 to 2.11.4 and 2.12.0 to 2.12.1, as well as rh-sso7-keycloak versions 0:9.0.15-1.redhat_00002.1.el6, 0:9.0.15-1.redhat_00002.1.el7, and 0:9.0.15-1.redhat_00002.1.el8.
To fix CVE-2020-28491, upgrade to com.fasterxml.jackson.dataformat:jackson-dataformat-cbor version 2.11.4 or 2.12.1, or rh-sso7-keycloak versions 0:9.0.15-1.redhat_00002.1.el6, 0:9.0.15-1.redhat_00002.1.el7, or 0:9.0.15-1.redhat_00002.1.el8.
You can find more information about CVE-2020-28491 at the following references: [1](https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6), [2](https://github.com/FasterXML/jackson-dataformats-binary/issues/186), [3](https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329).