Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p383-f595-x4qw

Опубликовано: 11 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

EPSS

Процентиль: 53%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-326
CWE-328
CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
nvd
больше 3 лет назад

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

CVSS3: 6.5
debian
больше 3 лет назад

The aeson library is not safe to use to consume untrusted JSON input. ...

CVSS3: 6.5
fstec
больше 3 лет назад

Уязвимость библиотеки анализа и кодирования JSON aeson, связанная с недостаточной стойкостью шифрования, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
redos
больше 1 года назад

Уязвимость ghc-aeson

EPSS

Процентиль: 53%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-326
CWE-328
CWE-400