RHSA-2023:2312MediumCVSS 7.5

Red Hat Security Advisory: jackson security update

Published
May 9, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects

🎯 Affected products12

  • Red Hat Enterprise Linux AppStream (v. 9)
  • jackson-annotations-0:2.14.1-1.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • jackson-core-0:2.14.1-2.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • jackson-databind-0:2.14.1-2.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • jackson-jaxrs-providers-0:2.14.1-2.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • jackson-modules-base-0:2.14.1-2.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-jackson-annotations-0:2.14.1-1.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-jackson-core-0:2.14.1-2.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-jackson-databind-0:2.14.1-2.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-jackson-jaxrs-json-provider-0:2.14.1-2.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-jackson-jaxrs-providers-0:2.14.1-2.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-jackson-module-jaxb-annotations-0:2.14.1-2.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (5)