Fiche vulnérabilité
CVE-2022-40149 : faille élevée jettison project jettison (CVSS 7.5)
Description
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 sept. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- jettison project jettison
- debian debian linux