-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Closed
Labels
LibrariesLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respoLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respo
Description
Summary
jackson-core versions 2.19.0 through 2.21.0 are affected by GHSA-72hv-8253-57qq. OpenSearch currently uses version 2.20.1. The patched version is 2.21.1.
Vulnerability
The non-blocking (async) JSON parser in jackson-core bypasses the maxNumberLength constraint (default: 1000 characters) in StreamReadConstraints, allowing arbitrarily long numbers that can cause memory and CPU exhaustion (DoS).
- Severity: HIGH
- CWE: CWE-770
- Affected package:
com.fasterxml.jackson.core:jackson-core2.19.0 β 2.21.0 - Fix: 2.21.1
Requested Action
Bump versions.jackson from 2.20.1 to 2.21.1 in the build plugin version catalog so all OpenSearch plugins pick up the fix.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
LibrariesLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respoLucene Upgrades and Libraries, Any 3rd party library that Core depends on, ex: nebula; team is respo