[ 
https://issues.apache.org/jira/browse/TOMEE-4227?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17785152#comment-17785152
 ] 

Richard Zowalla commented on TOMEE-4227:
----------------------------------------

Quoting from the Jackson issue tracker:

NOTE: the vendor's perspective is that this is not a valid vulnerability 
report, because the steps of constructing a cyclic data structure and trying to 
serialize it cannot be achieved by an external attacker

(See https://github.com/FasterXML/jackson-databind/issues/3972)





> Jackson 2.15.2
> --------------
>
>                 Key: TOMEE-4227
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4227
>             Project: TomEE
>          Issue Type: Dependency upgrade
>          Components: TomEE Core Server
>    Affects Versions: 8.0.15, 9.1.0
>            Reporter: Nikhil
>            Assignee: Richard Zowalla
>            Priority: Major
>              Labels: cve
>             Fix For: 10.0.0, 8.0.16, 9.1.1
>
>
> h1. Vulnerability Details
> h2. CVE-2023-35116
> {*}Summary{*}: An issue was discovered jackson-databind thru 2.15.2 allows 
> attackers to cause a denial of service or other unspecified impacts via 
> crafted object that uses cyclic dependencies. NOTE: the vendor's perspective 
> is that the product is not intended for use with untrusted input.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to