QID 355623
Date Published: 2023-07-24
QID 355623: Amazon Linux Security Advisory for jackson-core : ALAS2023-2023-248
An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. (
( CVE-2023-35116)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2023-2023-248 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2023-2023-248 -
alas.aws.amazon.com/AL2023/ALAS-2023-248.html
CVEs related to QID 355623
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-248 | amazon linux 2023 |
|