Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8p6-p27c-52fx

Опубликовано: 03 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Eclipse Parsson Denial of Service vulnerability

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.

To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

Пакеты

Наименование

org.eclipse.parsson:project

maven
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.4

1.1.4

Наименование

org.eclipse.parsson:project

maven
Затронутые версииВерсия исправления

< 1.0.5

1.0.5

EPSS

Процентиль: 36%
0.0015
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-834

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

CVSS3: 5.9
nvd
больше 2 лет назад

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

EPSS

Процентиль: 36%
0.0015
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-834