There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2023-1436:
(needs triaging)
An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-reference in one of its elements. This leads to a StackOverflowError exception being thrown.
- CVE-2023-5072:
(postponed; to be fixed through a stable update)
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
You can find information about how to handle these issues in the security team's documentation.