Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jettisonUpgrade jettison-javadoc | Dec 5, 2023 | Sep 16, 2022 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Mar 19, 2024 |
| Debian | — | Upgrade libjettison-java | Nov 11, 2022 | Sep 16, 2022 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Sep 20, 2022 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Sep 16, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 16, 2022 |
| Suse | — | Upgrade jettisonUpgrade jettison-javadoc | Mar 20, 2023 | Sep 16, 2022 |
| Ubuntu | — | Upgrade libjettison-java (Ubuntu Pro)Upgrade libjettison-java | Jun 20, 2023 | Sep 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub