Severity
7.5HIGH
EPSS
0.3%
top 49.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateNov 21

Description

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDfasterxml/jackson-databind2.13.02.13.4+1
Debianjackson-databind< 2.12.1-1+deb11u1+3
NVDquarkus/quarkus< 2.13.0

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

4
OSV
Uncontrolled Resource Consumption in FasterXML jackson-databind2022-10-03
GHSA
Uncontrolled Resource Consumption in FasterXML jackson-databind2022-10-03
OSV
CVE-2022-42004: In FasterXML jackson-databind before 22022-10-02
CVEList
CVE-2022-42004: In FasterXML jackson-databind before 22022-10-02

📋Vendor Advisories

6
Atlassian
CVE-2022-42004: Deserialization com.fasterxml.jackson.core:jackson-databind in Jira Software Data Center and Server2023-11-21
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (jackson-databind) — CVE-2022-420042023-10-15
Oracle
Oracle Oracle Supply Chain Risk Matrix: Security (jackson-databind) — CVE-2022-420042023-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Kafka) — CVE-2022-420042023-04-15
Red Hat
jackson-databind: use of deeply nested arrays2022-10-02