Files
CVEs-PoC/2020/CVE-2020-28491.md
T
2024-05-25 21:48:12 +02:00

20 lines
913 B
Markdown

### [CVE-2020-28491](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28491)
![](https://img.shields.io/static/v1?label=Product&message=com.fasterxml.jackson.dataformat%3Ajackson-dataformat-cbor&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3E%3D%200%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Denial%20of%20Service%20(DoS)&color=brighgreen)
### Description
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
### POC
#### Reference
- https://www.oracle.com/security-alerts/cpujul2022.html
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Live-Hack-CVE/CVE-2020-28491
- https://github.com/puppetlabs/security-snyk-clojure-action