CVE-2023-35116: Medium severity fasterxml jackson-databind vulnerability
DISPUTED jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
Other sources
An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
https://github.com/FasterXML/jackson-databind/issues/3972
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.15.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-35116.
What is the severity of CVE-2023-35116?
The severity of CVE-2023-35116 is medium with a severity value of 4.7.
Which software is affected by this vulnerability?
The FasterXML jackson-databind software up to version 2.15.2 is affected by this vulnerability.
What is the impact of this vulnerability?
This vulnerability allows attackers to cause a denial of service or other unspecified impact by using crafted objects with cyclic dependencies.
Is there a fix available for CVE-2023-35116?
At the moment, there is no information available about a fix for this vulnerability.