#VU16786 Input validation error in jackson-databind - CVE-2018-1000873
Published: January 4, 2019
jackson-databind
FasterXML
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into deserializing of crafted input with specifically very large values in the nanoseconds field of a time value and cause the service to crash.