CVE-2022-40149
published 2022-09-16CVE-2022-40149: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.34%
68.4th percentile
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libjettison-java | < libjettison-java 1.5.1-1 (bookworm) | libjettison-java 1.5.1-1 (bookworm) |
| jettison | jettison | unspecified – 1.4.0 | — |
| jettison_project | jettison | <= 1.4.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_oracle7.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2022-40149: DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-40149 [MEDIUM] CVE-2022-40149: DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
CVE-2022-40149: DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
DoS (Denial of Service) org.codehaus.jettison:jettison Dependency in Jira Software Data Center and Server
CVE: CVE-2022-40149
Affected products: Jira Software
Ubuntu
Jettison vulnerabilities
vendor_ubuntu·2023-06-19
CVE-2022-45685 Jettison vulnerabilities
Title: Jettison vulnerabilities
Summary: Several security issues were fixed in Jettison.
It was discovered that Jettison incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Build Scripts (Jettison) — CVE-2022-40149
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-40149 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Build Scripts (Jettison) — CVE-2022-40149
Oracle Oracle Fusion Middleware Risk Matrix: Build Scripts (Jettison) vulnerability
CVE: CVE-2022-40149
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Security (Jettison) — CVE-2022-40149
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-40149 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: Security (Jettison) — CVE-2022-40149
Oracle Oracle PeopleSoft Risk Matrix: Security (Jettison) vulnerability
CVE: CVE-2022-40149
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
jettison: parser crash by stackoverflow
vendor_redhat·2022-09-20·CVSS 6.5
CVE-2022-40149 [MEDIUM] CWE-787 jettison: parser crash by stackoverflow
jettison: parser crash by stackoverflow
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
A stack-based buffer overflow vulnerability was found in Jettison, where parsing an untrusted XML or JSON data may lead to a crash. This flaw allows an attacker to supply content that causes the parser to crash by writing outside the memory bounds if the parser is running on user-supplied input, resulting in a denial of service attack.
Package: jettison (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red
Debian
CVE-2022-40149: libjettison-java - Those using Jettison to parse untrusted XML or JSON data may be vulnerable to De...
vendor_debian·2022·CVSS 6.5
CVE-2022-40149 [MEDIUM] CVE-2022-40149: libjettison-java - Those using Jettison to parse untrusted XML or JSON data may be vulnerable to De...
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.5.1-1)
bullseye: resolved (fixed in 1.5.3-1~deb11u1)
forky: resolved (fixed in 1.5.1-1)
sid: resolved (fixed in 1.5.1-1)
trixie: resolved (fixed in 1.5.1-1)
GHSA
Jettison parser crash by stackoverflow
ghsa·2023-08-01·CVSS 7.5
CVE-2022-40149 [HIGH] CWE-121 Jettison parser crash by stackoverflow
Jettison parser crash by stackoverflow
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
### References
- https://nvd.nist.gov/vuln/detail/CVE-2022-40149
- https://github.com/jettison-json/jettison/issues/45
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538
- https://github.com/jettison-json/jettison/pull/49/files
- https://github.com/jettison-json/jettison/releases/tag/jettison-1.5.1
- https://lists.debian.org/debian-lts-announce/2022/11/msg00011.html
- https://www.debian.org/security/2023/dsa-5312
OSV
Jettison parser crash by stackoverflow
osv·2023-08-01·CVSS 7.5
CVE-2022-40149 [HIGH] Jettison parser crash by stackoverflow
Jettison parser crash by stackoverflow
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
### References
- https://nvd.nist.gov/vuln/detail/CVE-2022-40149
- https://github.com/jettison-json/jettison/issues/45
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538
- https://github.com/jettison-json/jettison/pull/49/files
- https://github.com/jettison-json/jettison/releases/tag/jettison-1.5.1
- https://lists.debian.org/debian-lts-announce/2022/11/msg00011.html
- https://www.debian.org/security/2023/dsa-5312
OSV
Jettison parser crash by stackoverflow
osv·2022-09-17
CVE-2022-40149 [MEDIUM] Jettison parser crash by stackoverflow
Jettison parser crash by stackoverflow
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
GHSA
Jettison parser crash by stackoverflow
ghsa·2022-09-17
CVE-2022-40149 [MEDIUM] CWE-121 Jettison parser crash by stackoverflow
Jettison parser crash by stackoverflow
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
OSV
CVE-2022-40149: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS)
osv·2022-09-16·CVSS 7.5
CVE-2022-40149 [HIGH] CVE-2022-40149: Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS)
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
No detection rules found.
No public exploits indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538https://github.com/jettison-json/jettison/issues/45https://lists.debian.org/debian-lts-announce/2022/11/msg00011.htmlhttps://www.debian.org/security/2023/dsa-5312https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538https://github.com/jettison-json/jettison/issues/45https://lists.debian.org/debian-lts-announce/2022/11/msg00011.htmlhttps://www.debian.org/security/2023/dsa-5312
2022-09-16
Published