Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45685

Опубликовано: 23 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

A flaw was found in Jettison. Sending a specially crafted string can cause a stack-based buffer overflow. This issue may allow a remote attacker to cause a denial of service.

Отчет

Red Hat has determined the impact of this flaw to be Moderate. A successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2jettisonNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Migration Toolkit for Applications 6org.keycloak-keycloak-parentNot affected
Migration Toolkit for Runtimesorg.keycloak-keycloak-parentNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat build of Apache Camel for Spring Boot 3jettisonAffected
Red Hat Data Grid 8jettisonNot affected
Red Hat Decision Manager 7jettisonOut of support scope
Red Hat Enterprise Linux 7jettisonOut of support scope
Red Hat Enterprise Linux 8log4j:2/log4jNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2214825jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data

EPSS

Процентиль: 33%
0.00131
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

CVSS3: 7.5
nvd
около 3 лет назад

A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

CVSS3: 7.5
debian
около 3 лет назад

A stack overflow in Jettison before v1.5.2 allows attackers to cause a ...

CVSS3: 7.5
github
около 3 лет назад

Jettison Out-of-bounds Write vulnerability

EPSS

Процентиль: 33%
0.00131
Низкий

7.5 High

CVSS3