Record summary

CVE-2022-42003 has a selected CVSS score of 7.5 (high).

Description

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

com.fasterxml.jackson.core:jackson-databind

Browse Maven / com.fasterxml.jackson.core:jackson-databind
GitHub Advisory2.4.0-rc1 to < 2.12.7.1 · Fixed in 2.12.7.1affected
2.13.0 to < 2.13.4.2 · Fixed in 2.13.4.2affected

References

Showing 12 of 18