VDB
RHSA-2022%3A0296
RHSA-2022%3A0296
PUBLISHED
CVSS 7.5 HIGH
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHPAM 7.12.0 |
Timeline
- Jun 28, 2021 PoC Published
- Dec 10, 2021 PoC Published
- Dec 11, 2021 PoC Published
- Dec 13, 2021 PoC Published
- Jan 26, 2022 CVE Published
- Jun 7, 2022 PoC Published
- Sep 16, 2022 PoC Published
- Nov 21, 2023 PoC Published
- Dec 8, 2023 PoC Published
- Dec 11, 2023 PoC Published
- Mar 1, 2024 PoC Published
- Apr 5, 2024 PoC Published
References
- https://access.redhat.com/errata/RHSA-2022:0296 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1966735 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997763 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997765 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997772 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997777 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997779 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997784 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1997793 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2030932 issue
- https://access.redhat.com/security/cve/CVE-2020-28491 advisory
- https://github.com/fabric8io/kubernetes-client/issues/2715 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-29505 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-29505 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-39139 advisory
- https://github.com/x-stream/xstream/security/advisories/GHSA-64xx-cq4q-mf44 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-39140 advisory
- https://github.com/x-stream/xstream/security/advisories/GHSA-6wf9-jmg9-vxcc advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-39141 advisory
- https://github.com/x-stream/xstream/security/advisories/GHSA-g5w6-mrj7-75h2 advisory
…and 78 more