Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5072

Опубликовано: 12 окт. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

A flaw was found in the org.json package. A bug in the parser exists, and an input string may lead to undefined usage of memory, leading to an out-of-memory error, causing a denial of service (DoS).

Отчет

This vulnerability may cause denial of service with a small string input, causing the server to be unresponsive easily, hence the Important impact.

Меры по смягчению последствий

No current mitigation is available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift ServerlessJSON-javaNot affected
Red Hat Ansible Automation Platform 2JSON-javaNot affected
Red Hat build of Apicurio Registry 2JSON-javaAffected
Red Hat build of Debezium 2JSON-javaNot affected
Red Hat Data Grid 8JSON-javaNot affected
Red Hat Decision Manager 7JSON-javaAffected
Red Hat Integration Camel Quarkus 2JSON-javaAffected
Red Hat JBoss Data Grid 7JSON-javaWill not fix
Red Hat JBoss Enterprise Application Platform 6jsonOut of support scope
Red Hat JBoss Enterprise Application Platform 7jsonNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2246417JSON-java: parser confusion leads to OOM

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

CVSS3: 7.5
nvd
около 2 лет назад

Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

CVSS3: 7.5
debian
около 2 лет назад

Denial of Service in JSON-Java versions up to and including 20230618. ...

CVSS3: 7.5
redos
больше 1 года назад

Уязвимость OpenSearch

CVSS3: 7.5
github
около 2 лет назад

Java: DoS Vulnerability in JSON-JAVA

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3