Resource Exhaustion in FasterXML Jackson Databind Product
CVE-2022-42003
7.5HIGH
What is CVE-2022-42003?
A resource exhaustion vulnerability exists in FasterXML's jackson-databind prior to version 2.14.0-rc1 due to an inadequate check in primitive value deserializers. This flaw can lead to excessive resource consumption when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled, resulting in potential application crashes or denial of service. It is critical for users to update to versions 2.13.4.1, 2.12.17.1, or newer to safeguard against this issue.
