Vulnerabilities > CVE-2022-42004 - Deserialization of Untrusted Data vulnerability in multiple products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Vulnerable Configurations

Part Description Count
Application
Fasterxml
181
Application
Quarkus
207
Application
Netapp
1
OS
Debian
2

Common Weakness Enumeration (CWE)