Details
-
Bug
-
Status: Resolved
-
Normal
-
Resolution: Fixed
-
None
-
Security - Denial of Service
-
Normal
-
Normal
-
User Report
-
All
-
None
-
Description
https://nvd.nist.gov/vuln/detail/CVE-2023-35116
An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that the product is not intended for use with untrusted input.