Описание
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
A flaw was found in Jackson Databind. This issue may allow a malicious user to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | jackson-databind | Not affected | ||
| Cryostat 2 | jackson-databind | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Not affected | ||
| Red Hat AMQ Broker 7 | jackson-databind | Not affected | ||
| Red Hat A-MQ Online | jackson-databind | Not affected | ||
| Red Hat build of Debezium 1 | jackson-databind | Not affected | ||
| Red Hat build of Quarkus | com.fasterxml.jackson.core/jackson-databind | Not affected | ||
| Red Hat Data Grid 8 | jackson-databind | Not affected | ||
| Red Hat Decision Manager 7 | jackson-databind | Out of support scope |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before ...
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
Уязвимость библиотеки jackson-databind, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3