QID 994787
Date Published: 2023-08-10
QID 994787: Java (Maven) Security Update for com.fasterxml.jackson.dataformat:jackson-dataformats-text (GHSA-rg2c-cfxv-qp6f)
Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rg2c-cfxv-qp6f for updates and patch information.
Vendor References
- GHSA-rg2c-cfxv-qp6f -
github.com/advisories/GHSA-rg2c-cfxv-qp6f
CVEs related to QID 994787
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rg2c-cfxv-qp6f | com.fasterxml.jackson.dataformat:jackson-dataformats-text |
|