In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-02T00:00:00
Updated: 2024-08-03T12:56:39.182Z
Reserved: 2022-10-02T00:00:00
Link: CVE-2022-42004
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-10-02T05:15:09.237
Modified: 2022-12-02T15:10:05.287
Link: CVE-2022-42004
Redhat