Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45693

Опубликовано: 13 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

A flaw was found in Jettison, where it is vulnerable to a denial of service caused by a stack-based buffer overflow. By sending a specially-crafted request using the map parameter, a remote attacker can cause a denial of service.

Отчет

Red Hat has determined the impact of this flaw to be Moderate; a successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2jettisonNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Migration Toolkit for Runtimesorg.keycloak-keycloak-parentAffected
Red Hat build of QuarkusjettisonNot affected
Red Hat Data Grid 8jettisonNot affected
Red Hat Decision Manager 7jettisonOut of support scope
Red Hat Enterprise Linux 7jettisonOut of support scope
Red Hat Enterprise Linux 8log4j:2/log4jNot affected
Red Hat Enterprise Linux 9log4jNot affected
Red Hat Fuse 7jettisonOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2155970jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos

EPSS

Процентиль: 33%
0.00131
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVSS3: 7.5
nvd
около 3 лет назад

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVSS3: 7.5
debian
около 3 лет назад

Jettison before v1.5.2 was discovered to contain a stack overflow via ...

CVSS3: 7.5
github
около 3 лет назад

Jettison Out-of-bounds Write vulnerability

EPSS

Процентиль: 33%
0.00131
Низкий

7.5 High

CVSS3