PT-2022-7225 · Atlassian+6 · Bamboo Data Center/Server+11

Published

2020-08-13

·

Updated

2025-01-28

·

CVE-2020-36518

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions jackson-databind versions prior to 2.13.0 Bitbucket Data Center and Server versions 7.17.0, 7.21.0, 8.7.0, 8.8.0, 8.9.0, 8.10.0, 8.11.0, 8.12.0, 8.13.0 Bitbucket Data Center and Server versions prior to 7.21.14, 8.9.4, 8.10.4, 8.11.3, 8.11.4, 8.12.1, 8.12.2, 8.13.1 Bamboo Data Center and Server versions 9.1.0, 9.2.1, 9.3.0 Bamboo Data Center and Server versions prior to 9.2.5, 9.3.3
Description The issue is related to a Java StackOverflow exception and denial of service via a large depth of nested objects in the jackson-databind library. This can be exploited by an unauthenticated attacker to cause a denial of service. The vulnerability affects various Atlassian products, including Bitbucket Data Center and Server, and Bamboo Data Center and Server.
Recommendations For jackson-databind versions prior to 2.13.0, upgrade to version 2.13.0 or later. For Bitbucket Data Center and Server versions 7.17.0, 7.21.0, 8.7.0, 8.8.0, 8.9.0, 8.10.0, 8.11.0, 8.12.0, 8.13.0, upgrade to a release greater than or equal to 7.21.14, 8.9.4, 8.10.4, 8.11.3, 8.11.4, 8.12.1, 8.12.2, 8.13.1. For Bamboo Data Center and Server versions 9.1.0, 9.2.1, 9.3.0, upgrade to a release greater than or equal to 9.2.5, 9.3.3. As a temporary workaround, consider restricting the use of the jackson-databind library to minimize the risk of exploitation.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2312
ALSA-2024:3061
BDU:2024-00114
CESA-2024_3061
CVE-2020-36518
DLA-2990-1
DLA-3207-1
DSA-5283-1
GHSA-57J2-W4CX-62H2
GHSA-Q95J-488Q-5Q3P
INFSA-2023_2312
INFSA-2024_3061
MGASA-2024-0069
OESA-2023-1921
OESA-2023-1971
OPENSUSE-SU-2022_1678-1
OPENSUSE-SU-2024:12096-1
OPENSUSE-SU-2024:12100-1
OPENSUSE-SU-2024:12101-1
RHSA-2022:4918
RHSA-2022:4919
RHSA-2022:6782
RHSA-2022:6783
RHSA-2022:7409
RHSA-2022:7410
RHSA-2022:7411
RHSA-2023:2312
RHSA-2023_2312
RHSA-2024:3061
RHSA-2024_3061
RHSA-2025:9582
RHSA-2025:9583
RLSA-2024:3061
ROSA-SA-2025-2629
SUSE-SU-2022:1678-1
SUSE-SU-2022_1678-1

Affected Products

Almalinux
Astra Linux
Bamboo
Bamboo Data Center/Server
Bitbucket
Bitbucket Data Center/Server
Centos
Jira
Jira Service Management Server
Red Hat
Rocky Linux
Suse