org.codehaus.jettison:jettison
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.codehaus.jettison:jettisonpage 1 of 1
- CVE-2022-40149MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.5.12022-09-16
vulnerable: 1.0 ... 1.5.0 (20 versions)
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow…
- CVE-2022-40150MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.5.22022-09-16
vulnerable: 1.0 ... 1.5.1 (21 versions)
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory…
- CVE-2022-45685HIGHCVSS 7.5EG 7.5✓ Fixed in 1.5.22022-12-13
vulnerable: 1.0 ... 1.5.1 (21 versions)
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
- CVE-2022-45693HIGHCVSS 7.5EG 7.5✓ Fixed in 1.5.22022-12-13
vulnerable: 1.0 ... 1.5.1 (21 versions)
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
- CVE-2023-1436MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.5.42023-03-22
vulnerable: 1.0 ... 1.5.3 (23 versions)
An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-reference in one of its elements. This leads to a StackOverflowError exception being thrown.
Check whether org.codehaus.jettison:jettison is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.codehaus.jettison:jettison CVEs against the assets you own.
Start Free Scan →