Описание
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-github-tidwall-gjson | fixed | 1.14.4-1 | experimental | package |
| golang-github-tidwall-gjson | fixed | 1.14.4-2 | package | |
| golang-github-tidwall-gjson | no-dsa | bookworm | package | |
| golang-github-tidwall-gjson | no-dsa | bullseye | package | |
| golang-github-tidwall-gjson | postponed | buster | package |
Примечания
https://github.com/tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944 (v1.9.2)
https://github.com/tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96 (v1.9.3)
https://github.com/tidwall/gjson/issues/236
https://github.com/tidwall/gjson/issues/237
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 4 лет назад
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVSS3: 7.5
nvd
больше 4 лет назад
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVSS3: 7.5
github
больше 4 лет назад
github.com/tidwall/gjson Vulnerable to REDoS attack