jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos
Published Dec 13, 2022
7.5
HIGHCVSS 3.1
EPSS 1.44%
Description
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
Affected products
No data.
Configuration 1
- < 1.5.2
Configuration 2
- 10.0
- 11.0
No data.
MTA-6.2-RHEL-8
mta/mta-rhel8-operator:6.2.2-3
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-hub-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-operator-bundle:6.2.2-5
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-pathfinder-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-ui-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-windup-addon-rhel9:6.2.2-3
Fixed · RHSA-2024:1027
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1686649756-1.el8
Fixed · RHSA-2023:3610
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-20
Fixed · RHSA-2023:1047
RHINT Camel-Springboot 3.14.5.P1
jettison
Fixed · RHSA-2023:0544
RHPAM 7.13.1 async
n/a
Fixed · RHSA-2023:2135
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-apache-cxf-0:3.1.16-4.redhat_00003.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jackson-databind-0:2.8.11.6-2.SP1_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jettison-0:1.3.8-2.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-netty-0:4.1.63-1.Final_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-resteasy-0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-snakeyaml-0:1.33.0-1.SP1_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-velocity-0:1.7.0-3.redhat_00006.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-0:7.1.9-2.GA_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:1746
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-java8-0:2.10.4-2.redhat_00004.1.el7eap
Fixed · RHSA-2025:1747
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jettison-0:1.5.2-2.redhat_00002.1.el7eap
Fixed · RHSA-2025:1747
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-resteasy-0:3.11.6-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2025:1747
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-jettison-0:1.5.2-1.redhat_00002.1.el8eap
Fixed · RHSA-2023:0553
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-jettison-0:1.5.2-1.redhat_00002.1.el9eap
Fixed · RHSA-2023:0554
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-jettison-0:1.5.2-1.redhat_00002.1.el7eap
Fixed · RHSA-2023:0552
Red Hat JBoss Enterprise Application Platform 7.4.9
org.codehaus.jettison/jettison:1.5.2.redhat-00002
Fixed · RHSA-2023:0556
Red Hat Single Sign-On 7
jettison
Fixed · RHSA-2023:1049
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:1043
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:1044
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:1045
A-MQ Clients 2
jettison
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel8
Not affected
Migration Toolkit for Runtimes
org.keycloak-keycloak-parent
Affected
Red Hat Data Grid 8
jettison
Not affected
Red Hat Decision Manager 7
jettison
Out of support scope
Red Hat Enterprise Linux 7
jettison
Out of support scope
Red Hat Enterprise Linux 8
log4j:2/log4j
Not affected
Red Hat Enterprise Linux 9
log4j
Not affected
Red Hat Fuse 7
jettison
Out of support scope
Red Hat Integration Camel K 1
jettison
Affected
Red Hat Integration Camel Quarkus 1
jettison
Not affected
Red Hat JBoss Data Grid 7
jettison
Out of support scope
Red Hat JBoss Data Virtualization 6
jettison
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
eap6-jettison
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jboss-on
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jbossas-modules-eap
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jettison
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_2-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_3-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_4-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_5-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform Expansion Pack
jettison
Affected
Red Hat JBoss Fuse 6
jettison
Out of support scope
Red Hat JBoss Fuse Service Works 6
jettison
Out of support scope
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Out of support scope
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Affected
Red Hat Process Automation 7
jettison
Out of support scope
Red Hat Satellite 6
jettison
Out of support scope
Red Hat build of Quarkus
jettison
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| MTA-6.2-RHEL-8 | mta/mta-rhel8-operator:6.2.2-3 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-hub-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-operator-bundle:6.2.2-5 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-pathfinder-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-ui-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-windup-addon-rhel9:6.2.2-3 | Fixed | RHSA-2024:1027 |
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1686649756-1.el8 | Fixed | RHSA-2023:3610 |
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-20 | Fixed | RHSA-2023:1047 |
| RHINT Camel-Springboot 3.14.5.P1 | jettison | Fixed | RHSA-2023:0544 |
| RHPAM 7.13.1 async | n/a | Fixed | RHSA-2023:2135 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-apache-cxf-0:3.1.16-4.redhat_00003.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jackson-databind-0:2.8.11.6-2.SP1_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jettison-0:1.3.8-2.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-netty-0:4.1.63-1.Final_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-resteasy-0:3.0.27-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-snakeyaml-0:1.33.0-1.SP1_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-velocity-0:1.7.0-3.redhat_00006.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-0:7.1.9-2.GA_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:1746 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-java8-0:2.10.4-2.redhat_00004.1.el7eap | Fixed | RHSA-2025:1747 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jettison-0:1.5.2-2.redhat_00002.1.el7eap | Fixed | RHSA-2025:1747 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-resteasy-0:3.11.6-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2025:1747 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-jettison-0:1.5.2-1.redhat_00002.1.el8eap | Fixed | RHSA-2023:0553 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-jettison-0:1.5.2-1.redhat_00002.1.el9eap | Fixed | RHSA-2023:0554 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-jettison-0:1.5.2-1.redhat_00002.1.el7eap | Fixed | RHSA-2023:0552 |
| Red Hat JBoss Enterprise Application Platform 7.4.9 | org.codehaus.jettison/jettison:1.5.2.redhat-00002 | Fixed | RHSA-2023:0556 |
| Red Hat Single Sign-On 7 | jettison | Fixed | RHSA-2023:1049 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:1043 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:1044 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:1045 |
| A-MQ Clients 2 | jettison | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | n/a |
| Migration Toolkit for Runtimes | org.keycloak-keycloak-parent | Affected | n/a |
| Red Hat Data Grid 8 | jettison | Not affected | n/a |
| Red Hat Decision Manager 7 | jettison | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | jettison | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | n/a |
| Red Hat Enterprise Linux 9 | log4j | Not affected | n/a |
| Red Hat Fuse 7 | jettison | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | jettison | Affected | n/a |
| Red Hat Integration Camel Quarkus 1 | jettison | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | jettison | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | jettison | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | eap6-jettison | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jboss-on | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossas-modules-eap | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jettison | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_2-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_3-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_4-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_5-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jettison | Affected | n/a |
| Red Hat JBoss Fuse 6 | jettison | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | jettison | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Affected | n/a |
| Red Hat Process Automation 7 | jettison | Out of support scope | n/a |
| Red Hat Satellite 6 | jettison | Out of support scope | n/a |
| Red Hat build of Quarkus | jettison | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has determined the impact of this flaw to be Moderate; a successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 22, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.44% (0.01435) | 72.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.40% (0.01395) | 68.75th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.13% (0.00126) | 32.68th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.22% (0.01221) | 77.31th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.10% (0.00101) | 25.57th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00104) | 44.36th | v3 (v2023.03.01) |
| Jul 5, 2024 | 0.10% (0.00096) | 40.53th | v3 (v2023.03.01) |
| May 25, 2024 | 0.07% (0.00069) | 29.90th | v3 (v2023.03.01) |
| Jan 15, 2024 | 0.06% (0.00062) | 24.77th | v3 (v2023.03.01) |
| Dec 20, 2023 | 0.07% (0.00065) | 27.01th | v3 (v2023.03.01) |
| Nov 13, 2023 | 0.05% (0.00053) | 19.52th | v3 (v2023.03.01) |
| May 8, 2023 | 0.05% (0.00047) | 14.49th | v3 (v2023.03.01) |
| Apr 17, 2023 | 0.05% (0.00052) | 18.47th | v3 (v2023.03.01) |
| Mar 22, 2023 | 0.06% (0.00055) | 20.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00047) | 14.28th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Jan 12, 2023 | 0.95% (0.00954) | 35.62th | v2 (v2022.01.01) |
| Dec 14, 2022 | 0.89% (0.00885) | 27.18th | v2 (v2022.01.01) |
References (8)
- https://access.redhat.com/security/cve/CVE-2022-45693 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2155970 Issue Tracking
- https://github.com/advisories/GHSA-grr4-wv38-f68w Advisory
- https://github.com/jettison-json/jettison/issues/52 ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00045.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45693
- https://www.cve.org/CVERecord?id=CVE-2022-45693
- https://www.debian.org/security/2023/dsa-5312 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-45693 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2155970 | Issue Tracking | |
| https://github.com/advisories/GHSA-grr4-wv38-f68w | Advisory | |
| https://github.com/jettison-json/jettison/issues/52 | ExploitIssue TrackingThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00045.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-45693 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-45693 | ||
| https://www.debian.org/security/2023/dsa-5312 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.