CVE-2022-45693
Aliases:GHSA-grr4-wv38-f68wDEBIAN-CVE-2022-45693CGA-2f49-8r4p-2f6gCGA-2h49-ch29-f4gqCGA-2p9f-278j-fxq5CGA-7476-5h84-qcmgCGA-7q22-pq53-rg8rCGA-8f33-6r64-xh2cCGA-8g5p-pgj8-8fcrCGA-h8gc-5hc4-rw88CGA-jqpv-hg9x-8gwwCGA-jx3m-qm97-vp6vCGA-mwf7-vm66-wvcjCGA-36m9-4gc8-r54xCGA-4484-w9hx-m63cCGA-vvmf-wj2h-qhg7
Advisory lineage Upstream: 0 Downstream: 15
Modified
Published: 13 Dec 2022, 00:00
Last modified:22 Apr 2025, 14:58
Vulnerability Summary
Overall Risk (default)
medium
40/100 CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
1.4% LOW
1% probability +1.26%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
13 Dec 2022, 00:00
Published
Vulnerability first disclosed
22 Apr 2025, 14:58
Last Modified
Vulnerability information updated
Description
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.40%• Percentile: 71%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- chainguard•druid
< 35.0.1-r0 | < 34.0.0-r6 | < 35.0.0-r0 | < 35.0.1-r5
- chainguard•hadoop-fips-3.3.6
all
- wolfi•druid
< 35.0.1-r0 | < 34.0.0-r6 | < 35.0.0-r0 | < 35.0.1-r5
- debian•libjettison-java
< 1.5.3-1~deb11u1 | < 1.5.3-1 | < 1.5.3-1 | < 1.5.3-1
- debian•debian_linux
10.0 | 11.0
- jettison_project•jettison
< 1.5.2
- org.codehaus.jettison•jettison
< 1.5.2
References (7)
- https://github.com/jettison-json/jettison/issues/52
- https://lists.debian.org/debian-lts-announce/2022/12/msg00045.html
- https://www.debian.org/security/2023/dsa-5312
- https://nvd.nist.gov/vuln/detail/CVE-2022-45693
- https://github.com/jettison-json/jettison
- https://security-tracker.debian.org/tracker/CVE-2022-45693
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45693.json