Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27568

Опубликовано: 23 фев. 2021
Источник: redhat
CVSS3: 5.9

Описание

An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

A flaw was found in json-smart. When an exception is thrown from a function, but is not caught, the program using the library may crash or expose sensitive information. The highest threat from this vulnerability is to data confidentiality and system availability. In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of json-smart package. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat JBoss Fuse 6json-smartOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch6Out of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hiveWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-metering-prestoWill not fix
Red Hat AMQ Streams 1.8.0json-smartFixedRHSA-2021:322519.08.2021
Red Hat Fuse 7.10json-smartFixedRHSA-2021:513414.12.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1939839json-smart: uncaught exception may lead to crash or information disclosure

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
почти 5 лет назад

An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

CVSS3: 5.9
github
больше 4 лет назад

Improper Check for Unusual or Exceptional Conditions in json-smart

CVSS3: 9.1
fstec
около 4 лет назад

Уязвимость библиотек json-smart-v1 и json-smart-v2, связанная с недостаточной проверкой необычных или исключительных состояний, позволяющая нарушителю вызвать аварийное завершение работы приложения или раскрыть защищаемую информацию

5.9 Medium

CVSS3