Description


Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Related CPE's



o

debian

debian_linux

2

Weaknesses



CWE-121


CWE-787

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-09-16T08:15:09.677Z

3 years ago

Last modified

2024-11-21T06:20:58.857Z

1 year ago