Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-42004

Опубликовано: 02 окт. 2022
Источник: debian

Описание

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jackson-databindfixed2.14.0-1package

Примечания

  • https://github.com/FasterXML/jackson-databind/issues/3582

  • https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88 (jackson-databind-2.13.4)

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

CVSS3: 7.5
redhat
больше 3 лет назад

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

CVSS3: 7.5
nvd
больше 3 лет назад

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

CVSS3: 7.5
github
больше 3 лет назад

Uncontrolled Resource Consumption in FasterXML jackson-databind

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость библиотеки Jackson-databind проекта FasterXML, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю вызвать отказ в обслуживании