SUSE-SU-2022:3995-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3995-1
SUSE-SU-2022:3995-1
Summary: Security update for jackson-databind
Details: This update for jackson-databind fixes the following issues: Update to version 2.13.4.2: - CVE-2022-42003: Fixed missing check in primitive value deserializers to avoid deep wrapper array nesting wrt 'UNWRAP_SINGLE_VALUE_ARRAYS' (bsc#1204370). - CVE-2022-42004: Fixed missing check in 'BeanDeserializer._deserializeFromArray()' to prevent use of deeply nested arrays (bsc#1204369).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223995-1/, https://bugzilla.suse.com/1204369, https://bugzilla.suse.com/1204370, https://www.suse.com/security/cve/CVE-2022-42003, https://www.suse.com/security/cve/CVE-2022-42004
Affected packages
Package
Name: jackson-databind
Purl: pkg:rpm/suse/jackson-databind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
