Denial of Service Vulnerability in Jackson Databind by FasterXML
CVE-2023-35116
4.7MEDIUM
What is CVE-2023-35116?
The Jackson Databind library, specifically versions up to 2.15.2, is susceptible to a denial of service attack through crafted object serialization involving cyclic dependencies. Although the vendor asserts that replicating this scenario via external exploitation is not feasible, the vulnerability highlights potential risks for applications utilizing this library under specific conditions. Developers should be aware of the intricacies of object construction and serialization processes to mitigate unintended impacts.
