vulnerability

Alma Linux: CVE-2020-36518: Moderate: jackson security update (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Mar 11, 2022
Added
May 15, 2023
Modified
Nov 13, 2025

Description

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Solutions

alma-upgrade-apache-commons-collectionsalma-upgrade-apache-commons-langalma-upgrade-apache-commons-netalma-upgrade-bea-stax-apialma-upgrade-fasterxml-oss-parentalma-upgrade-glassfish-fastinfosetalma-upgrade-glassfish-jaxb-apialma-upgrade-glassfish-jaxb-corealma-upgrade-glassfish-jaxb-runtimealma-upgrade-glassfish-jaxb-txw2alma-upgrade-jackson-annotationsalma-upgrade-jackson-bomalma-upgrade-jackson-corealma-upgrade-jackson-databindalma-upgrade-jackson-jaxrs-json-provideralma-upgrade-jackson-jaxrs-providersalma-upgrade-jackson-module-jaxb-annotationsalma-upgrade-jackson-modules-basealma-upgrade-jackson-parentalma-upgrade-jakarta-commons-httpclientalma-upgrade-javassistalma-upgrade-javassist-javadocalma-upgrade-pki-jackson-databindalma-upgrade-pki-servlet-enginealma-upgrade-relaxngdatatypealma-upgrade-slf4jalma-upgrade-slf4j-jdk14alma-upgrade-stax-exalma-upgrade-velocityalma-upgrade-xalan-j2alma-upgrade-xerces-j2alma-upgrade-xml-commons-apisalma-upgrade-xml-commons-resolveralma-upgrade-xmlstreambufferalma-upgrade-xsom
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.