Bug 13869

Summary: [CVE 21] jackson-dataformats-text 2.9.8 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: RESOLVED WONTFIX    
Severity: critical CC: e.kosachev, s.matveev, v.potapov, y.tumanov
Priority: Highest Flags: y.tumanov: secteam_verified?
Version: All   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2023-3894,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: Upstream:

Description Yury 2023-10-18 20:26:57 MSK
Please patch CVEs for package jackson-dataformats-text version 2.9.8
  
INFO (CVEs are): jackson-dataformats-text 2.9.8
 cves found
CVE-2023-3894
Desc: Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Link: https://nvd.nist.gov/vuln/detail/CVE-2023-3894
Severity: HIGH
Comment 1 Vladimir Potapov 2023-10-20 17:01:35 MSK
*** Bug 13737 has been marked as a duplicate of this bug. ***
Comment 2 Vladimir Potapov 2023-10-20 17:01:47 MSK
*** Bug 13544 has been marked as a duplicate of this bug. ***
Comment 3 Svyatoslav Matveev 2023-12-12 01:43:20 MSK
Входит в java-стек, который пока обновляться не будет