CVE-2022-42003

Published

Severity

CVSS v3:
7.5 HIGH
CVSS v2:
N/A

Description

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*n/a2.14.0*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*2.13.0 (including)2.13.4.1*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*n/a2.12.7.1*
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*n/a2.13.3*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*n/an/a11.0
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*n/an/a-

External Links