CVE-2022-40150

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.12 % (47th)
0.12% Progress
Affected Products 2
Advisories 4

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.

Weaknesses
CWE-400
Uncontrolled Resource Consumption
CWE-674
Uncontrolled Recursion
CVE Status
PUBLISHED
CNA
Google Inc.
Published Date
2022-09-16 10:15:09
(2 years ago)
Updated Date
2023-07-13 17:24:33
(14 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jettison Project Jettison 1.4.0 and prior versions cpe:2.3:a:jettison_project:jettison <= 1.4.0

Configuration #2

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
  Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...