HIGH7.5
GHSA-q6g2-g7f3-rr83
Jettison vulnerable to infinite recursion
Quick fix
GHSA-q6g2-g7f3-rr83 — org.codehaus.jettison:jettison: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.5.4</version> for org.codehaus.jettison:jettisonDetails
An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-reference in one of its elements. This leads to a StackOverflowError exception being thrown.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.codehaus.jettison:jettison
Introduced in:
0Fixed in: 1.5.4Fix
# pom.xml: bump <version>1.5.4</version> for org.codehaus.jettison:jettisonReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-1436[ADVISORY]
- https://github.com/jettison-json/jettison/issues/60[WEB]
- https://github.com/jettison-json/jettison/pull/62[WEB]
- https://github.com/jettison-json/jettison[PACKAGE]
- https://github.com/jettison-json/jettison/releases/tag/jettison-1.5.4[WEB]
- https://research.jfrog.com/vulnerabilities/jettison-json-array-dos-xray-427911[WEB]