2.0.1
10 years ago
10 months ago
Known vulnerabilities in the org.apache.johnzon:johnzon package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Deserialization of Untrusted Data. A malicious attacker can craft up a JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and maybe use numbers too large which may result in a slow conversion. How to fix Deserialization of Untrusted Data? Upgrade | [,1.2.21) |