logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-42004

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-42004

Description:
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
Last updated date:
12/02/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/04/2022
Reference url to background

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490

Type:
exploit
Confidence:
HIGH
Date of publishing:
10/04/2022
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy