Описание
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
A flaw was found in FasterXML jackson-databind. This issue could allow an attacker to benefit from resource exhaustion when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled due to unchecked primitive value deserializers to avoid deep wrapper array nesting.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | jackson-databind | Not affected | ||
| Red Hat A-MQ Online | jackson-databind | Not affected | ||
| Red Hat build of Apicurio Registry 2 | jackson-databind | Affected | ||
| Red Hat build of Debezium 1 | jackson-databind | Not affected | ||
| Red Hat Enterprise Linux 8 | jackson-databind | Affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/jackson-databind | Will not fix | ||
| Red Hat Enterprise Linux 9 | jackson-databind | Will not fix | ||
| Red Hat Fuse 7 | jackson-databind | Will not fix | ||
| Red Hat Integration Camel K 1 | jackson-databind | Affected | ||
| Red Hat Integration Service Registry | jackson-databind | Out of support scope |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, ...
Uncontrolled Resource Consumption in Jackson-databind
Уязвимость библиотеки Jackson-databind проекта FasterXML, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3