Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-35116

Опубликовано: 14 июн. 2023
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 4.7

Описание

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

disputed
esm-apps/bionic

not-affected

disputed
esm-apps/focal

not-affected

disputed
esm-apps/jammy

not-affected

disputed
esm-apps/noble

not-affected

disputed
esm-apps/xenial

not-affected

disputed
esm-infra-legacy/trusty

not-affected

disputed
focal

not-affected

disputed
jammy

not-affected

disputed

Показывать по

EPSS

Процентиль: 3%
0.00015
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
redhat
больше 2 лет назад

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.

CVSS3: 4.7
nvd
больше 2 лет назад

jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.

CVSS3: 4.7
debian
больше 2 лет назад

jackson-databind through 2.15.2 allows attackers to cause a denial of ...

CVSS3: 7.5
github
больше 2 лет назад

An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVSS3: 4.7
fstec
больше 2 лет назад

Уязвимость библиотеки Jackson-databind проекта FasterXML, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00015
Низкий

4.7 Medium

CVSS3