Bugzilla – Bug 1206401
VUL-0: CVE-2022-45693: jettison: StackOverflow when creating a JSON from a HashMap
Last modified: 2024-05-03 09:32:29 UTC
CVE-2022-45693 Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string. Upstream fix: https://github.com/jettison-json/jettison/commit/19ae19ff57d00dbfa6f6c3af4fc4cb14fb5ca2df References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45693 https://www.cve.org/CVERecord?id=CVE-2022-45693 https://github.com/jettison-json/jettison/issues/52
Affected: - SUSE:SLE-15-SP2:Update - openSUSE:Backports:SLE-15-SP3:Update - openSUSE:Factory
Time to close this one.
done, closing