Bug 13869

Summary: [CVE 21] jackson-dataformats-text 2.9.8 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: RESOLVED WONTFIX QA Contact: ROSA Linux Bugs <bugs>
Severity: critical    
Priority: Highest CC: e.kosachev, s.matveev, v.potapov, y.tumanov
Version: AllFlags: y.tumanov: secteam_verified?
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2023-3894,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-10-18 20:26:57 MSK
Please patch CVEs for package jackson-dataformats-text version 2.9.8
  
INFO (CVEs are): jackson-dataformats-text 2.9.8
 cves found
CVE-2023-3894
Desc: Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Link: https://nvd.nist.gov/vuln/detail/CVE-2023-3894
Severity: HIGH
Comment 1 Vladimir Potapov 2023-10-20 17:01:35 MSK
*** Bug 13737 has been marked as a duplicate of this bug. ***
Comment 2 Vladimir Potapov 2023-10-20 17:01:47 MSK
*** Bug 13544 has been marked as a duplicate of this bug. ***
Comment 3 Svyatoslav Matveev 2023-12-12 01:43:20 MSK
Входит в java-стек, который пока обновляться не будет