[Bugs] [Bug 13253] New: [CVE 21] jettison 1.3.7 CVEs found
bugzilla
bugzilla на rosalinux.ru
Вт Май 2 15:37:55 MSK 2023
https://bugzilla.rosalinux.ru/show_bug.cgi?id=13253
Platform: 2021.1
Bug ID: 13253
Summary: [CVE 21] jettison 1.3.7 CVEs found
Classification: ROSA-based products
Product: ROSA Fresh
Version: All
Hardware: All
URL: CVE-2022-45685, CVE-2022-45693, CVE-2023-1436,
OS: Linux
Status: CONFIRMED
Severity: normal
Priority: Normal
Component: System (kernel, glibc, systemd, bash, PAM...)
Assignee: bugs на lists.rosalinux.ru
Reporter: y.tumanov на rosalinux.ru
QA Contact: bugs на lists.rosalinux.ru
CC: s.matveev на rosalinux.ru, y.tumanov на rosalinux.ru
Target Milestone: ---
Flags: secteam_verified?
Please patch CVEs for package jettison version 1.3.7
INFO (CVEs are): jettison 1.3.7 cves found
CVE-2022-45685
Desc: A stack overflow in Jettison before v1.5.2 allows attackers to cause a
Denial of Service (DoS) via crafted JSON data.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-45685
Severity: HIGH
CVE-2022-45693
Desc: Jettison before v1.5.2 was discovered to contain a stack overflow via the
map parameter. This vulnerability allows attackers to cause a Denial of Service
(DoS) via a crafted string.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-45693
Severity: HIGH
CVE-2023-1436
Desc: An infinite recursion is triggered in Jettison when constructing a
JSONArray from a Collection that contains a self-reference in one of its
elements. This leads to a StackOverflowError exception being thrown.
Link: https://nvd.nist.gov/vuln/detail/CVE-2023-1436
Severity: HIGH
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
----------- следущая часть -----------
Вложение в формате HTML было извлечено…
URL: <http://lists.rosalinux.ru/pipermail/bugs/attachments/20230502/42032445/attachment.html>
Подробная информация о списке рассылки Bugs