Skip to content

Apiman Manager API affected by Jackson denial of service vulnerability

Moderate severity GitHub Reviewed Published Jan 5, 2023 in apiman/apiman • Updated Jan 9, 2023

Package

maven io.apiman:apiman-manager-api-impl (Maven)

Affected versions

<= 2.2.3.Final

Patched versions

3.0.0.Final

Description

Impact

Due to a vulnerability in jackson-databind <= 2.12.6.0, an authenticated attacker could craft an Apiman policy configuration which, when saved, may cause a denial of service on the Apiman Manager API.

This does not affect the Apiman Gateway.

Patches

Upgrade to Apiman 3.0.0.Final or later.

If you are using an older version of Apiman and need to remain on that version, contact your Apiman support provider for advice/long-term support.

Workarounds

If all users of the Apiman Manager are trusted then you may assess this is low risk, as an account is required to exploit the vulnerability.

References

References

@msavy msavy published to apiman/apiman Jan 5, 2023
Published to the GitHub Advisory Database Jan 9, 2023
Reviewed Jan 9, 2023
Last updated Jan 9, 2023

Severity

Moderate
6.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-q95j-488q-5q3p

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.