Out-of-bounds read In jackson-databind
Description
Deeply nested json in jackson-databind jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2.12.1-1+deb11u1 | ||
debian 12 | 2.13.2.2-1 | ||
debian 14 | 2.13.2.2-1 | ||
maven | 2.13.2.1, 2.12.6.1 | ||
debian 13 | 2.13.2.2-1 | ||
rpm rhel9 | 0:2.14.1-2.el9 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13.