Junglewise Threat Intelligence

CVE-2022-42004: FasterXML jackson-databind resource exhaustion in BeanDeserializer

CVE-2022-42004 · Severity: high · CVSS 7.5 · Published 2022-10-03

Technologies: FasterXML Jackson Databind. Vendors: FasterXML.

Executive brief

FasterXML jackson-databind is a popular Java library used for converting data between Java objects and JSON. A vulnerability in how it handles specific data structures could allow an attacker to crash an application by sending a specially crafted request. This results in a denial-of-service, potentially making the affected system or service unavailable to legitimate users.

Technical details

A resource exhaustion vulnerability exists in FasterXML jackson-databind's BeanDeserializer._deserializeFromArray method. The component fails to properly validate or limit the depth of nested arrays during deserialization. This issue is specifically exploitable when the `UNWRAP_SINGLE_VALUE_ARRAYS` configuration is explicitly enabled. A remote, unauthenticated attacker can provide a maliciously crafted JSON payload with deeply nested arrays to trigger excessive resource consumption, leading to a Denial of Service (DoS). The vulnerability is addressed in versions 2.12.7.1 and 2.13.4.

Affected products

  • FasterXML jackson-databind >= 2.4.0-rc1, < 2.12.7.1; >= 2.13.0, < 2.13.4

Timeline

  • 2022-10-02: disclosed: NVD publication date
  • 2022-10-03: advisory: GitHub Advisory published

References

Related threats