PT-2022-6919 · Atlassian+4 · Bitbucket Server+9

Published

2022-10-02

·

Updated

2025-01-28

·

CVE-2022-42004

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions prior to 2.13.4 Bamboo Data Center and Server versions 9.1.0, 9.2.1, and 9.3.0 Bitbucket Data Center and Server versions 7.17.0, 7.21.0, 8.7.0, 8.8.0, 8.9.0, 8.10.0, 8.11.0, 8.12.0, and 8.13.0
Description The issue is related to resource exhaustion due to a lack of a check in BeanDeserializer. deserializeFromArray to prevent use of deeply nested arrays. This can occur when the UNWRAP SINGLE VALUE ARRAYS feature is explicitly enabled. An application is vulnerable only with certain customized choices for deserialization. The vulnerability allows an unauthenticated attacker to expose assets in the environment susceptible to exploitation, with no impact to confidentiality, no impact to integrity, and high impact to availability, requiring no user interaction.
Recommendations For FasterXML jackson-databind versions prior to 2.13.4, upgrade to version 2.13.4 or later. For Bamboo Data Center and Server version 9.2, upgrade to a release greater than or equal to 9.2.5. For Bamboo Data Center and Server version 9.3, upgrade to a release greater than or equal to 9.3.3. For Bitbucket Data Center and Server version 7.21, upgrade to a release greater than or equal to 7.21.14. For Bitbucket Data Center and Server version 8.9, upgrade to a release greater than or equal to 8.9.4. For Bitbucket Data Center and Server version 8.10, upgrade to a release greater than or equal to 8.10.4. For Bitbucket Data Center and Server version 8.11, upgrade to a release greater than or equal to 8.11.3 or 8.11.4. For Bitbucket Data Center and Server version 8.12, upgrade to a release greater than or equal to 8.12.1 or 8.12.2. For Bitbucket Data Center and Server version 8.13, upgrade to a release greater than or equal to 8.13.1.

Exploit

Fix

DoS

Resource Exhaustion

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05617
CVE-2022-42004
DLA-3207-1
DSA-5283-1
GHSA-RGV9-Q543-RQG4
MGASA-2024-0069
OESA-2023-1921
OESA-2023-1971
OPENSUSE-SU-2022_3995-1
OPENSUSE-SU-2024:12412-1
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RHSA-2023:1043
RHSA-2023:1044
RHSA-2023:1045
RHSA-2023:1064
RHSA-2023:2097
RHSA-2023:3663
RHSA-2025:1746
RHSA-2025:1747
RLSA-2023:2097
ROSA-SA-2025-2629
SUSE-SU-2022:3995-1

Affected Products

Astra Linux
Bamboo
Bamboo Server
Bitbucket
Bitbucket Server
Jira
Jira Service Management Server
Rocky Linux
Suse
Jackson-Databind