Описание
github.com/tidwall/gjson Vulnerable to REDoS attack
GJSON is a Go package that provides a fast and simple way to get values from a json document. GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-42836
- https://github.com/tidwall/gjson/issues/236
- https://github.com/tidwall/gjson/issues/237
- https://github.com/tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944
- https://github.com/tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96
- https://github.com/tidwall/gjson/compare/v1.9.2...v1.9.3
- https://pkg.go.dev/vuln/GO-2021-0265
Пакеты
Наименование
github.com/tidwall/gjson
go
Затронутые версииВерсия исправления
< 1.9.3
1.9.3
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 4 лет назад
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVSS3: 7.5
nvd
больше 4 лет назад
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVSS3: 7.5
debian
больше 4 лет назад
GJSON before 1.9.3 allows a ReDoS (regular expression denial of servic ...