Описание
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
A flaw was found in the Jackson Databind package. This cause of the issue is due to a Java StackOverflow exception and a denial of service via a significant depth of nested objects.
Отчет
CodeReady Studio is no longer supported and therefore this flaw will not be addressed in CodeReady Studio.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
A-MQ Clients 2 | jackson-databind | Not affected | ||
Red Hat A-MQ Online | jackson-databind | Not affected | ||
Red Hat BPM Suite 6 | jackson-databind | Out of support scope | ||
Red Hat build of Apicurio Registry 2 | jackson-databind | Affected | ||
Red Hat build of Debezium 1 | jackson-databind | Will not fix | ||
Red Hat CodeReady Studio 12 | jackson-databind | Out of support scope | ||
Red Hat Integration Camel K 1 | jackson-databind | Affected | ||
Red Hat Integration Service Registry | jackson-databind | Out of support scope | ||
Red Hat JBoss A-MQ 6 | jackson-databind | Out of support scope | ||
Red Hat JBoss BRMS 6 | jackson-databind | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
jackson-databind before 2.13.0 allows a Java StackOverflow exception a ...
ELSA-2024-3061: pki-core:10.6 and pki-deps:10.6 security update (MODERATE)
EPSS
7.5 High
CVSS3