FasterXML Jackson-databind 2.14.0 Release Candidate 1

CPE Details

FasterXML Jackson-databind 2.14.0 Release Candidate 1
2.14.0
2022-10-03
11h13 +00:00
2023-09-12
18h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fasterxml:jackson-databind:2.14.0:rc1:*:*:*:*:*:*

Informations

Vendor

fasterxml

Product

jackson-databind

Version

2.14.0

Update

rc1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-35116 2023-06-13 22h00 +00:00 jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
4.7
Medium