Описание
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| jackson-databind | fixed | 2.13.2.2-1 | package |
Примечания
https://github.com/FasterXML/jackson-databind/issues/2816
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 4 года назад
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
CVSS3: 7.5
redhat
больше 5 лет назад
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
CVSS3: 7.5
nvd
почти 4 года назад
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.