GHSA-9fwf-46g9-45rx

Suggest an improvement
Source
https://github.com/advisories/GHSA-9fwf-46g9-45rx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-9fwf-46g9-45rx/GHSA-9fwf-46g9-45rx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9fwf-46g9-45rx
Aliases
  • CVE-2022-40154
Withdrawn
2022-12-06T13:41:12Z
Published
2022-09-17T00:00:41Z
Modified
2026-09-10T03:49:45Z
Summary
Denial of Service via stack overflow
Details

Withdrawn

This advisory has been withdrawn because it has been found to be a duplicate. Please see the issue here for more information.

Original Despcription

Those using FasterXML/woodstox to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.

This vulnerability is only relevant for users making use of the DTD parsing functionality.

Database specific
{
    "cwe_ids": [
        "CWE-787"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-09-21T20:50:31Z",
    "nvd_published_at": "2022-09-16T10:15:00Z",
    "severity": "LOW"
}
References

Affected packages

Maven / com.fasterxml.woodstox:woodstox-core

Package

Name
com.fasterxml.woodstox:woodstox-core
View open source insights on deps.dev
Purl
pkg:maven/com.fasterxml.woodstox/woodstox-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.4.0

Affected versions

6.*
6.0.0
6.0.0.pr1
6.0.0.pr2
6.0.1
6.0.2
6.0.3
6.1.0
6.1.1
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.3.0
6.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-9fwf-46g9-45rx/GHSA-9fwf-46g9-45rx.json"

Maven / com.fasterxml.woodstox:woodstox-core

Package

Name
com.fasterxml.woodstox:woodstox-core
View open source insights on deps.dev
Purl
pkg:maven/com.fasterxml.woodstox/woodstox-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.4.0

Affected versions

5.*
5.0.0
5.0.1
5.0.2
5.0.3
5.1.0
5.2.0
5.2.1
5.3.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-9fwf-46g9-45rx/GHSA-9fwf-46g9-45rx.json"