Описание
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| jayway-jsonpath | not-affected | package |
Примечания
https://github.com/json-path/JsonPath/issues/973
https://github.com/json-path/JsonPath/pull/985
Fixed by: https://github.com/json-path/JsonPath/commit/71a09c1193726c010917f1157ecbb069ad6c3e3b (json-path-2.9.0)
Introduced in: https://github.com/json-path/JsonPath/commit/454b7d49a34246b3629c7a20adefe503859aad34 (2.2.0)
EPSS
Связанные уязвимости
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
Уязвимость функции Criteria.parse() Java-библиотеки JsonPath, позволяющая нарушителю вызвать отказ в обслуживании
EPSS