Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-35116
HistoryJun 14, 2023 - 12:00 a.m.

CVE-2023-35116

2023-06-1400:00:00
ubuntu.com
ubuntu.com
301
cve-2023-35116
denial of service
crafted object
cyclic dependencies
disputed
upstream

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%

DISPUTED jackson-databind through 2.15.2 allows attackers to cause a
denial of service or other unspecified impact via a crafted object that
uses cyclic dependencies. NOTE: the vendor’s perspective is that this is
not a valid vulnerability report, because the steps of constructing a
cyclic data structure and trying to serialize it cannot be achieved by an
external attacker.

Notes

Author Note
sbeattie attack vector of a crafted string disputed by upstream

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%