Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.apiman/apiman-manager-api-impl
  4. ›
  5. GMS-2023-7

GMS-2023-7: Apiman Manager API affected by Jackson denial of service vulnerability

January 9, 2023

Impact

Due to a vulnerability in jackson-databind <= 2.12.6.0, an authenticated attacker could craft an Apiman policy configuration which, when saved, may cause a denial of service on the Apiman Manager API.

This does not affect the Apiman Gateway.

Patches

Upgrade to Apiman 3.0.0.Final or later.

If you are using an older version of Apiman and need to remain on that version, contact your Apiman support provider for advice/long-term support.

Workarounds

If all users of the Apiman Manager are trusted then you may assess this is low risk, as an account is required to exploit the vulnerability.

References

  • Apiman maintainer and security contact: marc@blackparrotlabs.io
  • https://nvd.nist.gov/vuln/detail/CVE-2020-36518
  • https://github.com/FasterXML/jackson-databind/issues/2816

References

  • github.com/FasterXML/jackson-databind/issues/2816
  • github.com/advisories/GHSA-q95j-488q-5q3p
  • github.com/apiman/apiman/security/advisories/GHSA-q95j-488q-5q3p
  • nvd.nist.gov/vuln/detail/CVE-2020-36518

Code Behaviors & Features

Detect and mitigate GMS-2023-7 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.2.3.final

Fixed versions

  • 3.0.0.Final

Solution

Upgrade to version 3.0.0.Final or above.

Source file

maven/io.apiman/apiman-manager-api-impl/GMS-2023-7.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:50 +0000.