You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/6.3.1/bf29b07ca4dd81ef3c0bc18c8bd5617510a81c5d/woodstox-core-6.3.1.jar
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
mend-for-github.aaakk.us.kgbot
changed the title
CVE-2022-40156 (High) detected in woodstox-core-6.3.1.jar, woodstox-core-6.2.7.jar
CVE-2022-40156 (High) detected in woodstox-core-6.3.1.jar
Nov 8, 2022
CVE-2022-40156 - High Severity Vulnerability
Woodstox is a high-performance XML processor that implements Stax (JSR-173), SAX2 and Stax2 APIs
Library home page: https://github.com/FasterXML/woodstox
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.woodstox/woodstox-core/6.3.1/bf29b07ca4dd81ef3c0bc18c8bd5617510a81c5d/woodstox-core-6.3.1.jar
Dependency Hierarchy:
Found in HEAD commit: e89d66259a7e239dd3b023916815ce42b084b121
Found in base branch: master
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
Publish Date: 2022-09-16
URL: CVE-2022-40156
Base Score Metrics:
Type: Upgrade version
Release Date: 2022-09-16
Fix Resolution: com.fasterxml.woodstox:woodstox-core:5.4.0,6.4.0
The text was updated successfully, but these errors were encountered: