Описание
Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
Ссылки
- Issue TrackingPatchThird Party Advisory
- Release Notes
- Patch
- Issue TrackingPatchThird Party Advisory
- Release Notes
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 2.15.0 (исключая)
cpe:2.3:a:fasterxml:jackson-dataformats-text:*:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.0005
Низкий
5.8 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-20
CWE-787
Связанные уязвимости
EPSS
Процентиль: 15%
0.0005
Низкий
5.8 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-20
CWE-787