Amazon Linux 2023 Security Advisory: ALAS-2023-428
Advisory Release Date: 2023-10-30 23:44 Pacific
Advisory Updated Date: 2023-11-03 22:41 Pacific
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization. (CVE-2021-46877)
Affected Packages:
jackson-databind
Issue Correction:
Run dnf update jackson-databind --releasever 2023.2.20231030 to update your system.
noarch:
jackson-databind-2.11.4-6.amzn2023.0.2.noarch
src:
jackson-databind-2.11.4-6.amzn2023.0.2.src