Описание
Out of bounds read in json-smart
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions prior to 1.3.3 and 2.4.5 which causes a denial of service (DOS) via a crafted web request.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-31684
- https://github.com/netplex/json-smart-v1/issues/10
- https://github.com/netplex/json-smart-v2/issues/67
- https://github.com/netplex/json-smart-v1/pull/11
- https://github.com/netplex/json-smart-v2/pull/68
- https://lists.debian.org/debian-lts-announce/2023/03/msg00030.html
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Пакеты
net.minidev:json-smart
>= 1.3.0, < 1.3.3
1.3.3
net.minidev:json-smart
>= 2.4.0, < 2.4.4
2.4.4
Связанные уязвимости
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
A vulnerability was discovered in the indexOf function of JSONParserBy ...
Уязвимость функции indexOf() класса JSONParserByteArray библиотеки JSON Smart, позволяющая нарушителю вызвать отказ в обслуживании