Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21653

Опубликовано: 05 янв. 2022
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Jawn is an open source JSON parser. Extenders of the org.typelevel.jawn.SimpleFacade and org.typelevel.jawn.MutableFacade who don't override objectContext() are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. jawn-parser-1.3.1 fixes this issue and users are advised to upgrade. For users unable to upgrade override objectContext() to use a collision-safe collection.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:typelevel:jawn:*:*:*:*:*:*:*:*
Версия до 1.3.2 (исключая)

EPSS

Процентиль: 35%
0.00141
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
CWE-326

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 4 лет назад

Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.

CVSS3: 5.9
debian
около 4 лет назад

Jawn is an open source JSON parser. Extenders of the `org.typelevel.ja ...

suse-cvrf
около 4 лет назад

Security update for jawn

suse-cvrf
около 4 лет назад

Security update for jawn

CVSS3: 5.9
github
около 4 лет назад

Hash collision in typelevel jawn

EPSS

Процентиль: 35%
0.00141
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
CWE-326