Back

HIGH

jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos

Published Dec 13, 2022

Description

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

Affected products

Remediation

Red Hat statement

Red Hat has determined the impact of this flaw to be Moderate; a successful attack using this flaw would require the processing of untrusted, unsanitized, or unrestricted user inputs, which runs counter to established Red Hat security practices.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 13, 2022
Updated Apr 22, 2025
Reserved Nov 21, 2022
CISA Vulnrichment
Updated Apr 22, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 13, 2022
GHSA-GRR4-WV38-F68W