FasterXML Jackson-databind 2.13.1

CPE Details

FasterXML Jackson-databind 2.13.1
2.13.1
2022-09-07
13h15 +00:00
2023-09-12
18h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fasterxml:jackson-databind:2.13.1:*:*:*:*:*:*:*

Informations

Vendor

fasterxml

Product

jackson-databind

Version

2.13.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-35116 2023-06-13 22h00 +00:00 jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
4.7
Medium
CVE-2022-42003 2022-10-01 22h00 +00:00 In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
7.5
High
CVE-2022-42004 2022-10-01 22h00 +00:00 In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
7.5
High
CVE-2020-36518 2022-03-10 23h00 +00:00 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
7.5
High