GHSA-3f7h-mf4q-vrm4

Suggest an improvement
Source
https://github.com/advisories/GHSA-3f7h-mf4q-vrm4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-3f7h-mf4q-vrm4/GHSA-3f7h-mf4q-vrm4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3f7h-mf4q-vrm4
Aliases
Published
2022-09-17T00:00:41Z
Modified
2023-11-01T04:59:53.593342Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of Service due to parser crash
Details

Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

This vulnerability is only relevant for users making use of the DTD parsing functionality.

References

Affected packages

Maven / com.fasterxml.woodstox:woodstox-core

Package

Name
com.fasterxml.woodstox:woodstox-core
View open source insights on deps.dev
Purl
pkg:maven/com.fasterxml.woodstox/woodstox-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.4.0

Affected versions

6.*

6.0.0
6.0.0.pr1
6.0.0.pr2
6.0.1
6.0.2
6.0.3
6.1.0
6.1.1
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.3.0
6.3.1

Maven / com.fasterxml.woodstox:woodstox-core

Package

Name
com.fasterxml.woodstox:woodstox-core
View open source insights on deps.dev
Purl
pkg:maven/com.fasterxml.woodstox/woodstox-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0

Affected versions

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.2.0
5.2.1
5.3.0