MGASA-2024-0069

Source
https://advisories.mageia.org/MGASA-2024-0069.html
Import Source
https://advisories.mageia.org/MGASA-2024-0069.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0069
Related
Published
2024-03-16T16:28:17Z
Modified
2024-03-16T16:16:14Z
Summary
Updated jackson-databind packages fix security vulnerabilities
Details

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAPSINGLEVALUEARRAYS feature is enabled. (CVE-2022-42003) In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer.deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. (CVE-2022-42004)

References
Credits

Affected packages

Mageia:9 / jackson-databind

Package

Name
jackson-databind
Purl
pkg:rpm/mageia/jackson-databind?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.11.4-2.1.mga9

Ecosystem specific

{
    "section": "core"
}