FlawAtlas
Search the atlas
ALSA-2024:3061 Not scored

Moderate: pki-core:10.6 and pki-deps:10.6 security update

The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System. Security Fix(es): * jackson-databind: denial of service via a large depth of nested objects (CVE-2020-36518) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Exploit probability Not scored
Published May 22, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 jackson-jaxrs-providers
AlmaLinux:8 velocity
AlmaLinux:8 apache-commons-collections
AlmaLinux:8 pki-servlet-engine
AlmaLinux:8 stax-ex
AlmaLinux:8 fasterxml-oss-parent
AlmaLinux:8 glassfish-jaxb-runtime
AlmaLinux:8 xmlstreambuffer
AlmaLinux:8 glassfish-jaxb-api
AlmaLinux:8 bea-stax-api
AlmaLinux:8 slf4j
AlmaLinux:8 jackson-module-jaxb-annotations
AlmaLinux:8 glassfish-jaxb-txw2
AlmaLinux:8 jackson-modules-base
AlmaLinux:8 jackson-parent
AlmaLinux:8 jackson-core
AlmaLinux:8 xalan-j2
AlmaLinux:8 jakarta-commons-httpclient
AlmaLinux:8 jackson-annotations
AlmaLinux:8 xml-commons-apis
AlmaLinux:8 jackson-bom
AlmaLinux:8 jackson-jaxrs-json-provider
AlmaLinux:8 javassist
AlmaLinux:8 apache-commons-lang
AlmaLinux:8 jackson-databind
AlmaLinux:8 xsom
AlmaLinux:8 relaxngDatatype
AlmaLinux:8 xml-commons-resolver
AlmaLinux:8 xerces-j2
AlmaLinux:8 glassfish-jaxb-core
AlmaLinux:8 javassist-javadoc
AlmaLinux:8 apache-commons-net
AlmaLinux:8 glassfish-fastinfoset
AlmaLinux:8 slf4j-jdk14

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2024:3061

The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System. Security Fix(es): * jackson-databind: denial of service via a large depth of nested objects (CVE-2020-36518) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

View original source

05 / REFERENCES

Further evidence