Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7649
HistoryOct 26, 2018 - 6:49 a.m.

Denial Of Service (DoS)

2018-10-2606:49:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.005 Low

EPSS

Percentile

76.9%

jackson-datatype-jsr310 is vulnerable to denial of service. The deserialize function in DurationDeserializer and _fromDecimal function InstantDeserializer takes a long period of time to process when parsing big JSON numbers as Instant/ZonedDateTime/OffsetDateTime object, which can result in a denial of service condition.

References