Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37393
HistoryOct 03, 2022 - 10:42 a.m.

Denial Of Service (DoS)

2022-10-0310:42:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.003 Low

EPSS

Percentile

65.3%

com.fasterxml.jackson.core:jackson-databind is vulnerable to Denial Of Service (DoS). The vulnerability exists in _deserializeWrappedValue function in StdDeserializer.java, which allows an attacker to cause denial of service conditions via a maliciously crafted input, due to the resource exhaustion which occurs when processing a deeply nested array .