jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
References
Link | Resource |
---|---|
https://github.com/FasterXML/jackson-databind/issues/3972 | Issue Tracking |
Configurations
History
07 Nov 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
Summary | jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker. |
26 Jul 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | ** DISPUTED ** jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker. |
14 Jul 2023, 18:52
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-770 |
13 Jul 2023, 16:45
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
References | (MISC) https://github.com/FasterXML/jackson-databind/issues/3972 - Issue Tracking |
26 Jun 2023, 16:52
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/FasterXML/jackson-databind/issues/3972 - Exploit, Issue Tracking | |
CPE | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | |
CWE | CWE-502 | |
First Time |
Fasterxml jackson-databind
Fasterxml |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
19 Jun 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary | ** DISPUTED ** An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that the product is not intended for use with untrusted input. |
14 Jun 2023, 15:30
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-14 14:15
Updated : 2024-08-02 17:15
NVD link : CVE-2023-35116
Mitre link : CVE-2023-35116
CVE.ORG link : CVE-2023-35116
JSON object : View
Products Affected
fasterxml
- jackson-databind
CWE
CWE-770
Allocation of Resources Without Limits or Throttling