Menu

#32 jackson-core-2.11.3 - vulnerability

Any
closed-fixed
rzo
None
5
2024-11-15
2024-06-25
Ravi Raj
No

Blackduck Scan: BDSA-2022-4307

Description
FasterXML Jackson Core does not restrict the size of certain numeric types. A remote attacker able to supply specially crafted serialized data to an application that deserializes it, could cause excessive resource consumption resulting in a denial-of-service (DoS).

Discussion

  • rzo

    rzo - 2024-07-02
    • status: open --> open-accepted
     
  • rzo

    rzo - 2024-11-15
    • status: open-accepted --> closed-fixed
     
  • rzo

    rzo - 2024-11-15

    13.13

     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.