jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data
Published Dec 13, 2022
7.5
HIGHCVSS 3.1
EPSS 1.44%
Description
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
Affected products
No data.
Configuration 1
- < 1.5.2
Configuration 2
- 10.0
- 11.0
No data.
Red Hat build of Apache Camel 3.20.6 for Spring Boot
jettison
Fixed · RHSA-2024:3708
A-MQ Clients 2
jettison
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel8
Not affected
Migration Toolkit for Applications 6
org.keycloak-keycloak-parent
Not affected
Migration Toolkit for Runtimes
org.keycloak-keycloak-parent
Not affected
OpenShift Developer Tools and Services
jenkins-2-plugins
Affected
Red Hat Data Grid 8
jettison
Not affected
Red Hat Decision Manager 7
jettison
Out of support scope
Red Hat Enterprise Linux 7
jettison
Out of support scope
Red Hat Enterprise Linux 8
log4j:2/log4j
Not affected
Red Hat Enterprise Linux 9
log4j
Not affected
Red Hat Fuse 7
jettison
Out of support scope
Red Hat Integration Camel K 1
jettison
Will not fix
Red Hat Integration Camel Quarkus 1
jettison
Not affected
Red Hat JBoss Data Grid 7
jettison
Out of support scope
Red Hat JBoss Data Virtualization 6
jettison
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
eap6-jettison
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jboss-on
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jbossas-modules-eap
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jettison
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_2-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_3-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_4-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_5-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jettison
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jettison
Not affected
Red Hat JBoss Fuse 6
jettison
Out of support scope
Red Hat JBoss Fuse Service Works 6
jettison
Out of support scope
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Out of support scope
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Not affected
Red Hat Process Automation 7
jettison
Out of support scope
Red Hat Satellite 6
jettison
Out of support scope
Red Hat Single Sign-On 7
jettison
Not affected
Red Hat build of Apache Camel for Spring Boot 3
jettison
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Apache Camel 3.20.6 for Spring Boot | jettison | Fixed | RHSA-2024:3708 |
| A-MQ Clients 2 | jettison | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | n/a |
| Migration Toolkit for Applications 6 | org.keycloak-keycloak-parent | Not affected | n/a |
| Migration Toolkit for Runtimes | org.keycloak-keycloak-parent | Not affected | n/a |
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | n/a |
| Red Hat Data Grid 8 | jettison | Not affected | n/a |
| Red Hat Decision Manager 7 | jettison | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | jettison | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | n/a |
| Red Hat Enterprise Linux 9 | log4j | Not affected | n/a |
| Red Hat Fuse 7 | jettison | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | jettison | Will not fix | n/a |
| Red Hat Integration Camel Quarkus 1 | jettison | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | jettison | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | jettison | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | eap6-jettison | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jboss-on | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossas-modules-eap | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jettison | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_2-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_3-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_4-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_5-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jettison | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jettison | Not affected | n/a |
| Red Hat JBoss Fuse 6 | jettison | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | jettison | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Not affected | n/a |
| Red Hat Process Automation 7 | jettison | Out of support scope | n/a |
| Red Hat Satellite 6 | jettison | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | jettison | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | jettison | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has determined the impact of this flaw to be Moderate. A successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-45685 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2214825 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7554 Advisory
- https://github.com/advisories/GHSA-7rf3-mqpx-h7xg Advisory
- https://github.com/jettison-json/jettison/issues/54 ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00045.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45685
- https://www.cve.org/CVERecord?id=CVE-2022-45685
- https://www.debian.org/security/2023/dsa-5312 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-45685 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2214825 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7554 | Advisory | |
| https://github.com/advisories/GHSA-7rf3-mqpx-h7xg | Advisory | |
| https://github.com/jettison-json/jettison/issues/54 | ExploitIssue TrackingThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00045.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-45685 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-45685 | ||
| https://www.debian.org/security/2023/dsa-5312 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.