Jettison is vulnerable to denial of service. The vulnerability exists in nextValue()
function in JSONTokener.java
where the attacker may supply content that causes the parser to crash by out of memory if the parser is running on user supplied input.
bugs.chromium.org/p/oss-fuzz/issues/detail?id=46549
github.com/advisories/GHSA-x27m-9w8j-5vcw
github.com/jettison-json/jettison/commit/d3714681f61581810680df8e45858a4d30a602da
github.com/jettison-json/jettison/issues/45
lists.debian.org/debian-lts-announce/2022/12/msg00045.html
www.debian.org/security/2023/dsa-5312