Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3433

Опубликовано: 10 окт. 2022
Источник: debian
EPSS Низкий

Описание

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
haskell-aesonfixed2.0.3.0-1package
haskell-aesonno-dsabullseyepackage
haskell-aesonno-dsabusterpackage
haskell-aesonno-dsastretchpackage

Примечания

  • https://cs-syd.eu/posts/2021-09-11-json-vulnerability

  • https://github.com/haskell/aeson/issues/864

  • https://github.com/haskell/aeson/commit/582a844d8028f62e409048a4caae187b27e8e697 (v2.0.1.0)

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
nvd
больше 2 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
redos
11 месяцев назад

Уязвимость ghc-aeson

CVSS3: 6.5
github
больше 2 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость библиотеки анализа и кодирования JSON aeson, связанная с недостаточной стойкостью шифрования, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 31%
0.00115
Низкий