OESA-2023-1971
Dashboard / Vulnerabilities / OESA-2023-1971
OESA-2023-1971
Summary: jackson-databind security update
Details: The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration. Security Fix(es): jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.(CVE-2020-36518) In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.(CVE-2022-42003) In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.(CVE-2022-42004)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1971, https://nvd.nist.gov/vuln/detail/CVE-2020-36518, https://nvd.nist.gov/vuln/detail/CVE-2022-42003, https://nvd.nist.gov/vuln/detail/CVE-2022-42004
Affected packages
Package
Name: jackson-databind
Purl: pkg:rpm/openEuler/jackson-databind&distro=openEuler-20.03-LTS-SP4
Affected ranges
Type: ECOSYSTEM
Events:
