Description

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

com.fasterxml.jackson.core:jackson-databind

Browse Maven / com.fasterxml.jackson.core:jackson-databind
GitHub Advisory2.4.0-rc1 to < 2.12.7.1 · Fixed in 2.12.7.1affected
2.13.0 to < 2.13.4 · Fixed in 2.13.4affected

References

12