CVE-2022-45685
Aliases:GHSA-7rf3-mqpx-h7xgDEBIAN-CVE-2022-45685CGA-5w67-5867-w3qcCGA-65wr-8xwf-f9f5CGA-6c42-849w-h7v2CGA-884v-79j6-c5mmCGA-9jrf-9wxr-gp4xCGA-gcpq-f8f9-4hxcCGA-gpx7-395x-9v7fCGA-h6hf-26m5-h7h8CGA-3h37-pr79-2v8gCGA-638w-pprw-r3jrCGA-r5rp-2gxf-h5q2CGA-rwj8-q82g-59hfCGA-wxwg-xgp9-pcprCGA-x9xq-jg5g-hmmf
Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 13 Dec 2022, 00:00
Last modified:22 Apr 2025, 03:14
Vulnerability Summary
Overall Risk (default)
medium
40/100 CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
1.4% LOW
1% probability +1.26%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
13 Dec 2022, 00:00
Published
Vulnerability first disclosed
22 Apr 2025, 03:14
Last Modified
Vulnerability information updated
Description
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.40%• Percentile: 71%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- chainguard•druid
< 35.0.0-r0 | < 35.0.1-r0 | < 35.0.1-r5 | < 34.0.0-r6
- chainguard•hadoop-fips-3.3.6
all
- wolfi•druid
< 35.0.0-r0 | < 35.0.1-r0 | < 35.0.1-r5 | < 34.0.0-r6
- debian•libjettison-java
< 1.5.3-1~deb11u1 | < 1.5.3-1 | < 1.5.3-1 | < 1.5.3-1
- debian•debian_linux
10.0 | 11.0
- jettison_project•jettison
< 1.5.2
- org.codehaus.jettison•jettison
< 1.5.2
References (7)
- https://github.com/jettison-json/jettison/issues/54
- https://lists.debian.org/debian-lts-announce/2022/12/msg00045.html
- https://www.debian.org/security/2023/dsa-5312
- https://nvd.nist.gov/vuln/detail/CVE-2022-45685
- https://github.com/jettison-json/jettison
- https://security-tracker.debian.org/tracker/CVE-2022-45685
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45685.json