Описание
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
A flaw was found In FasterXML jackson-databind. This issue could allow an attacker to benefit from resource exhaustion due to the lack of a check in BeanDeserializer._deserializeFromArray to prevent the use of deeply nested arrays. An application is only vulnerable with certain customized choices for deserialization.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | jackson-databind | Not affected | ||
| Red Hat A-MQ Online | jackson-databind | Not affected | ||
| Red Hat build of Apicurio Registry 2 | jackson-databind | Affected | ||
| Red Hat build of Debezium 1 | jackson-databind | Not affected | ||
| Red Hat Enterprise Linux 8 | jackson-databind | Affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/jackson-databind | Will not fix | ||
| Red Hat Enterprise Linux 9 | jackson-databind | Will not fix | ||
| Red Hat Fuse 7 | jackson-databind | Will not fix | ||
| Red Hat Integration Camel K 1 | jackson-databind | Affected | ||
| Red Hat Integration Service Registry | jackson-databind | Out of support scope |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
In FasterXML jackson-databind before 2.13.4, resource exhaustion can o ...
Uncontrolled Resource Consumption in FasterXML jackson-databind
Уязвимость библиотеки Jackson-databind проекта FasterXML, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3