Details
-
Dependency upgrade
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
8.0.15, 9.1.0
Description
Vulnerability Details
CVE-2023-35116
Summary: An issue was discovered jackson-databind thru 2.15.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that the product is not intended for use with untrusted input.
Attachments
Issue Links
- is a clone of
-
TOMEE-4216 Jackson 2.15.1
- Resolved