Related Vulnerabilities: CVE-2020-36518  

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Description

The MITRE CVE dictionary describes this issue as:

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Additional Information

  • Bugzilla 2064698: CVE-2020-36518 jackson-databind: denial of service via a large depth of nested objects
  • FAQ: Frequently asked questions about CVE-2020-36518