Vendor
medium
advisory
FasterXML Jackson-databind Information Disclosure Vulnerability
1 CVEA vulnerability in FasterXML Jackson-databind identified as CVE-2024-42572 allows a remote unauthenticated attacker to exploit polymorphic type handling for information disclosure.
Jackson-databind
1c
medium
advisory
FasterXML Jackson Denial of Service Vulnerability
1 TTPA vulnerability in the FasterXML Jackson library allows remote, anonymous attackers to trigger a Denial of Service (DoS) condition by manipulating data processed by the library.
Jackson
1t
medium
advisory
Jackson-core Async Parser Max Number Length Bypass via Chunked Digit Accumulation
1 TTPAn incomplete fix for GHSA-72hv-8253-57qq in `jackson-core` versions 2.18.6, 2.21.1, and potentially 3.0.x/3.1.x, allows attackers to bypass `maxNumberLength` constraints in the non-blocking JSON parser by streaming JSON numbers in small chunks, leading to unbounded memory accumulation and denial of service in reactive applications.
jackson-core +3
java
json
serialization
memory-exhaustion
denial-of-service
1t