Amazon Linux 2023 Security Advisory: ALAS2023-2023-428
Advisory Released Date: 2023-11-03
Advisory Updated Date: 2023-11-03
Severity:
Low
Issue Overview:
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization. (CVE-2021-46877)
Affected Packages:
jackson-databind
Issue Correction:
Run dnf update jackson-databind --releasever 2023.2.20231030 to update your system.
New Packages:
noarch:
jackson-databind-2.11.4-6.amzn2023.0.2.noarch
src:
jackson-databind-2.11.4-6.amzn2023.0.2.src