CVE-2022-40149

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.16 % (53th)
0.16% Progress
Affected Products 2
Advisories 4

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Weaknesses
CWE-121
Stack-based Buffer Overflow
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
Google Inc.
Published Date
2022-09-16 10:15:09
(2 years ago)
Updated Date
2023-03-01 16:32:14
(18 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jettison Project Jettison 1.4.0 and prior versions cpe:2.3:a:jettison_project:jettison <= 1.4.0

Configuration #2

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
  Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...