PT-2022-6920 · Atlassian+4 · Bamboo Data Center/Server+9

Cowtowncoder

·

Published

2022-10-02

·

Updated

2026-06-04

·

CVE-2022-42003

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions 2.4.0-rc1 through 2.12.7.1 FasterXML jackson-databind versions 2.13.x through 2.13.4.1 Bamboo Data Center and Server versions 9.1.0 through 9.2.4 Bamboo Data Center and Server versions 9.3.0 through 9.3.2 Bitbucket Data Center and Server versions 7.17.0 through 7.21.13 Bitbucket Data Center and Server versions 8.7.0 through 8.9.3 Bitbucket Data Center and Server versions 8.10.0 through 8.10.3 Bitbucket Data Center and Server versions 8.11.0 through 8.11.2 Bitbucket Data Center and Server versions 8.12.0 through 8.12.0 Bitbucket Data Center and Server versions 8.13.0 through 8.13.0
Description The issue is related to resource exhaustion due to a lack of a check in primitive value deserializers to avoid deep wrapper array nesting when the UNWRAP SINGLE VALUE ARRAYS feature is enabled. This can allow an unauthenticated attacker to expose assets in the environment susceptible to exploitation, with no impact to confidentiality, no impact to integrity, and high impact to availability, requiring no user interaction.
Recommendations For FasterXML jackson-databind versions 2.4.0-rc1 through 2.12.7.1, upgrade to version 2.12.7.1 or later. For FasterXML jackson-databind versions 2.13.x through 2.13.4.1, upgrade to version 2.13.4.2 or later. For Bamboo Data Center and Server versions 9.1.0 through 9.2.4, upgrade to version 9.2.5 or later. For Bamboo Data Center and Server versions 9.3.0 through 9.3.2, upgrade to version 9.3.3 or later. For Bitbucket Data Center and Server versions 7.17.0 through 7.21.13, upgrade to version 7.21.14 or later. For Bitbucket Data Center and Server versions 8.7.0 through 8.9.3, upgrade to version 8.9.4 or later. For Bitbucket Data Center and Server versions 8.10.0 through 8.10.3, upgrade to version 8.10.4 or later. For Bitbucket Data Center and Server versions 8.11.0 through 8.11.2, upgrade to version 8.11.3 or later. For Bitbucket Data Center and Server versions 8.12.0 through 8.12.0, upgrade to version 8.12.1 or later. For Bitbucket Data Center and Server versions 8.13.0 through 8.13.0, upgrade to version 8.13.1 or later.

Exploit

Fix

DoS

Resource Exhaustion

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05618
CVE-2022-42003
DLA-3207-1
DSA-5283-1
GHSA-JJJH-JJXP-WPFF
MGASA-2024-0069
OESA-2023-1921
OESA-2023-1971
OPENSUSE-SU-2022_3995-1
OPENSUSE-SU-2024:12412-1
OPENSUSE-SU-2024:14395-1
RHSA-2023:0261
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RHSA-2023:1043
RHSA-2023:1044
RHSA-2023:1045
RHSA-2023:1064
RHSA-2023:1151
RHSA-2023:2097
RHSA-2023:3663
RHSA-2025:1746
RHSA-2025:1747
RLSA-2023:2097
ROSA-SA-2025-2629
SUSE-SU-2022:3995-1
SUSE-SU-2022_3995-1

Affected Products

Astra Linux
Bamboo
Bamboo Data Center/Server
Bitbucket
Bitbucket Data Center/Server
Jira
Jira Service Management Server
Rocky Linux
Suse
Jackson-Databind