Miggo Logo

CVE-2020-36518: Deeply nested json in jackson-databind

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.64596%
Published
3/12/2022
Updated
3/15/2024
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
com.fasterxml.jackson.core:jackson-databindmaven>= 2.13.0, <= 2.13.2.02.13.2.1
com.fasterxml.jackson.core:jackson-databindmaven<= 2.12.6.02.12.6.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

j**kson-**t**in* is * **t*-*in*in* p**k*** *or t** J**kson **t* Pro**ssor. j**kson-**t**in* *llows * J*v* st**k ov*r*low *x**ption *n* **ni*l o* s*rvi** vi* * l*r** **pt* o* n*st** o*j**ts.

Reasoning

No *n*lysis *v*il**l*