#VU68635 Deserialization of Untrusted Data in jackson-databind - CVE-2022-42003
Published: October 25, 2022 / Updated: February 11, 2025
jackson-databind
FasterXML
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insecure input validation when processing serialized data when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. A remote attacker can pass specially crafted data to the application and cause a denial of service condition on the target system.