Vulnerability Description
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Databind | < 2.16.0 |
Related Weaknesses (CWE)
References
- https://github.com/FasterXML/jackson-databind/issues/3972Issue Tracking
- https://github.com/FasterXML/jackson-databind/issues/3972Issue Tracking
FAQ
What is CVE-2023-35116?
CVE-2023-35116 is a vulnerability with a CVSS score of 4.7 (MEDIUM). jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that thi...
How severe is CVE-2023-35116?
CVE-2023-35116 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-35116?
Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind.