CVE-2020-28491 - High Severity Vulnerability
Vulnerable Library - jackson-dataformat-cbor-2.10.3.jar
Support for reading and writing Concise Binary Object Representation
([CBOR](https://www.rfc-editor.org/info/rfc7049)
encoded data using Jackson abstractions (streaming API, data binding, tree model)
Library home page: http://github.com/FasterXML/jackson-dataformats-binary
Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.dataformat/jackson-dataformat-cbor/bundles/jackson-dataformat-cbor-2.10.3.jar
Dependency Hierarchy:
- play-logback_2.13-2.8.2.jar (Root Library)
- play_2.13-2.8.2.jar
- akka-serialization-jackson_2.13-2.6.5.jar
- ❌ jackson-dataformat-cbor-2.10.3.jar (Vulnerable Library)
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
Vulnerability Details
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Publish Date: 2021-02-18
URL: CVE-2020-28491
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28491
Release Date: 2021-02-18
Fix Resolution (com.fasterxml.jackson.dataformat:jackson-dataformat-cbor): 2.11.4
Direct dependency fix Resolution (com.typesafe.play:play-logback_2.13): 2.8.8
CVE-2020-28491 - High Severity Vulnerability
Support for reading and writing Concise Binary Object Representation ([CBOR](https://www.rfc-editor.org/info/rfc7049) encoded data using Jackson abstractions (streaming API, data binding, tree model)
Library home page: http://github.com/FasterXML/jackson-dataformats-binary
Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.dataformat/jackson-dataformat-cbor/bundles/jackson-dataformat-cbor-2.10.3.jar
Dependency Hierarchy:
Found in HEAD commit: 2819174635979a19573ec0ce8e3e2b63a3848079
Found in base branch: master
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Publish Date: 2021-02-18
URL: CVE-2020-28491
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28491
Release Date: 2021-02-18
Fix Resolution (com.fasterxml.jackson.dataformat:jackson-dataformat-cbor): 2.11.4
Direct dependency fix Resolution (com.typesafe.play:play-logback_2.13): 2.8.8