Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p383-f595-x4qw

Опубликовано: 11 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

EPSS

Процентиль: 31%
0.00115
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-326
CWE-328
CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
nvd
больше 2 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
debian
больше 2 лет назад

The aeson library is not safe to use to consume untrusted JSON input. ...

CVSS3: 6.5
redos
11 месяцев назад

Уязвимость ghc-aeson

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость библиотеки анализа и кодирования JSON aeson, связанная с недостаточной стойкостью шифрования, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 31%
0.00115
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-326
CWE-328
CWE-400