Impact
Potential Denial-of-Service when attacker sends deeply nested JSON if (and only if) service:
- Reads deeply nested (1000s of levels) JSON as
JsonNode (ObjectMapper.readTree())
- Writes out same (or modifided) node using
JsonNode.toString()
which can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB).
Patches
Fixed in 2.14.0 via #3447 .
Workarounds
Avoid serializing JsonNode using toString(): use ObjectMapper.writeValueAsString(node)
References
Impact
Potential Denial-of-Service when attacker sends deeply nested JSON if (and only if) service:
JsonNode(ObjectMapper.readTree())JsonNode.toString()which can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB).
Patches
Fixed in 2.14.0 via #3447 .
Workarounds
Avoid serializing
JsonNodeusingtoString(): use ObjectMapper.writeValueAsString(node)References