Lucene search

K
githubGitHub Advisory DatabaseGHSA-3X8X-79M2-3W2W
HistoryMar 19, 2023 - 12:30 a.m.

jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode

2023-03-1900:30:25
GitHub Advisory Database
github.com
26
jackson-databind
denial of service
jdk serialization
2.10.x
2.12.x
2.13.x
2 gb
jsonnode
software

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

46.0%

jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.

Affected configurations

Vulners
Node
com.fasterxml.jackson.corejackson-databindRange2.13.0–2.13.1
OR
com.fasterxml.jackson.corejackson-databindRange2.10.0–2.12.6
VendorProductVersionCPE
com.fasterxml.jackson.corejackson-databind*cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

46.0%