jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
High severity
GitHub Reviewed
Published
Mar 19, 2023
to the GitHub Advisory Database
•
Updated Mar 23, 2023
Package
Affected versions
>= 2.10.0, < 2.12.6
>= 2.13.0, < 2.13.1
Patched versions
2.12.6
2.13.1
Description
Published by the National Vulnerability Database
Mar 18, 2023
Published to the GitHub Advisory Database
Mar 19, 2023
Reviewed
Mar 20, 2023
Last updated
Mar 23, 2023
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
References