Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35116

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.

Отчет

This CVE is disputed by the component developers and is under reconsideration by NIST. As such, it should be excluded from scanning utilities or other compliance systems until the dispute is finalized.

Меры по смягчению последствий

jackson-databind should not be used to deserialize untrusted inputs. User inputs should be validated and sanitized before processing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2jackson-databindNot affected
Cryostat 2jackson-databindWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat A-MQ Onlinejackson-databindNot affected
Red Hat build of Apache Camel for Spring Boot 3jackson-databindAffected
Red Hat build of Apicurio Registry 2jackson-databindAffected
Red Hat build of Debezium 1jackson-databindAffected
Red Hat build of Debezium 2jackson-databindAffected
Red Hat build of OptaPlanner 8jackson-databindWill not fix
Red Hat Decision Manager 7jackson-databindWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2215214jackson-databind: denial of service via cylic dependencies

EPSS

Процентиль: 3%
0.00015
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 2 лет назад

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.

CVSS3: 4.7
nvd
больше 2 лет назад

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.

CVSS3: 4.7
debian
больше 2 лет назад

jackson-databind through 2.15.2 allows attackers to cause a denial of ...

CVSS3: 7.5
github
больше 2 лет назад

An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVSS3: 4.7
fstec
больше 2 лет назад

Уязвимость библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00015
Низкий

4.7 Medium

CVSS3