Skip to content

Commit 8c08811

Browse files
author
yair
committed
[GHSA-xqcq-j8w9-3pxv] imporve: add CVE number
The cve-id somehow did not make it to the final advisory
1 parent 7c50876 commit 8c08811

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

advisories/github-reviewed/2023/08/GHSA-xqcq-j8w9-3pxv/GHSA-xqcq-j8w9-3pxv.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
"modified": "2023-08-01T19:53:16Z",
55
"published": "2023-08-01T19:53:16Z",
66
"aliases": [
7-
7+
"CVE-2022-40149"
88
],
99
"summary": "Jettison parser crash by stackoverflow",
1010
"details": "Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.\n\n### References\n\n- https://nvd.nist.gov/vuln/detail/CVE-2022-40149\n- https://github.com/jettison-json/jettison/issues/45\n- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538\n- https://github.com/jettison-json/jettison/pull/49/files\n- https://github.com/jettison-json/jettison/releases/tag/jettison-1.5.1\n- https://lists.debian.org/debian-lts-announce/2022/11/msg00011.html\n- https://www.debian.org/security/2023/dsa-5312",

0 commit comments

Comments
 (0)