CVE-2020-28491
published 2021-02-18CVE-2020-28491: This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.07%
86.2th percentile
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jackson-dataformat-cbor | < jackson-dataformat-cbor 2.7.8-5.1 (forky) | jackson-dataformat-cbor 2.7.8-5.1 (forky) |
| fasterxml | jackson-dataformats-binary | < 2.11.4 | 2.11.4 |
| fasterxml | jackson-dataformats-binary | < 2.12.1 | 2.12.1 |
| fasterxml | jackson-dataformats-binary | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| quarkus | quarkus | < 2.0.2 | 2.0.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of Service (DoS) in Jackson Dataformat CBOR
osv·2021-12-09
CVE-2020-28491 [HIGH] Denial of Service (DoS) in Jackson Dataformat CBOR
Denial of Service (DoS) in Jackson Dataformat CBOR
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 2.8.0-rc1 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
GHSA
Denial of Service (DoS) in Jackson Dataformat CBOR
ghsa·2021-12-09
CVE-2020-28491 [HIGH] CWE-770 Denial of Service (DoS) in Jackson Dataformat CBOR
Denial of Service (DoS) in Jackson Dataformat CBOR
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 2.8.0-rc1 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
OSV
CVE-2020-28491: This affects the package com
osv·2021-02-18·CVSS 7.5
CVE-2020-28491 [HIGH] CVE-2020-28491: This affects the package com
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third Party Jars (jackson-dataformats-binary) — CVE-2020-28491
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2020-28491 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third Party Jars (jackson-dataformats-binary) — CVE-2020-28491
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third Party Jars (jackson-dataformats-binary) vulnerability
CVE: CVE-2020-28491
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
vendor_redhat·2021-02-18·CVSS 7.5
CVE-2020-28491 [HIGH] CWE-400 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Statement: In OpenShift Container Platform (OCP), the hive/presto/hadoop components that comprise the OCP metering stack, ship the vulnerable version of jackson-dataformat-cbor.
Since the release of OCP 4.6, the metering product has been deprecated [1], hence the affected components are marked as wontfix.
This may be fixed in the future.
In OCP 4.6 the openshift4/ose-logging-elasticsearch6 container delivers the vulnerable version of jackson-dataformat-cb
Debian
CVE-2020-28491: jackson-dataformat-cbor - This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbo...
vendor_debian·2020·CVSS 7.5
CVE-2020-28491 [HIGH] CVE-2020-28491: jackson-dataformat-cbor - This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbo...
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.8-5.1)
sid: resolved (fixed in 2.7.8-5.1)
trixie: resolved (fixed in 2.7.8-5.1)
No detection rules found.
No public exploits indexed.
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
Bugzilla
CVE-2020-28491 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
bugzilla·2021-02-18·CVSS 7.5
CVE-2020-28491 [HIGH] CVE-2020-28491 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
CVE-2020-28491 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6
https://github.com/FasterXML/jackson-dataformats-binary/issues/186
https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329
Discussion:
This issue has been addressed in the following products:
vertx 4.1.2
Via RHSA-2021:3125 https://access.redhat.com/errata/RHSA-2021:3125
---
This bug is now closed. Further updates for in
https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6https://github.com/FasterXML/jackson-dataformats-binary/issues/186https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6https://github.com/FasterXML/jackson-dataformats-binary/issues/186https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329https://www.oracle.com/security-alerts/cpujul2022.html
2021-02-18
Published