Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
References
Link | Resource |
---|---|
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50083 | Issue Tracking Patch Third Party Advisory |
https://github.com/FasterXML/jackson-dataformats-text/blob/2.16/release-notes/VERSION-2.x | Release Notes |
https://github.com/FasterXML/jackson-dataformats-text/pull/398 | Patch |
Configurations
History
15 Aug 2023, 19:28
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-787 | |
CPE | cpe:2.3:a:fasterxml:jackson-dataformats-text:*:*:*:*:*:*:*:* | |
References | (MISC) https://github.com/FasterXML/jackson-dataformats-text/pull/398 - Patch | |
References | (MISC) https://github.com/FasterXML/jackson-dataformats-text/blob/2.16/release-notes/VERSION-2.x - Release Notes | |
References | (MISC) https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50083 - Issue Tracking, Patch, Third Party Advisory |
08 Aug 2023, 18:32
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-08 18:15
Updated : 2024-02-05 00:01
NVD link : CVE-2023-3894
Mitre link : CVE-2023-3894
CVE.ORG link : CVE-2023-3894
JSON object : View
Products Affected
fasterxml
- jackson-dataformats-text