Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-7272

Опубликовано: 17 июл. 2024
Источник: redhat
CVSS3: 6.8

Описание

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.

A flaw was found in Eclipse Parsson. A document containing a large depth of nested objects may allow an attacker to cause a Java stack overflow exception, potentially leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3parssonNot affected
OpenShift ServerlessparssonNot affected
Red Hat build of Apache Camel 4 for Quarkus 3parssonNot affected
Red Hat build of Apache Camel for Spring Boot 3parssonNot affected
Red Hat build of Apache Camel - HawtIO 4parssonNot affected
Red Hat build of Apicurio Registry 2parssonNot affected
Red Hat build of Quarkusorg.eclipse.parsson.jakarta.jsonNot affected
Red Hat build of Quarkusorg.eclipse.parsson.parssonNot affected
Red Hat Fuse 7parssonOut of support scope
Red Hat JBoss Enterprise Application Platform 7org.eclipse.parsson-projectNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2298458parsson: stack overflow when parsing deeply nested input

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
около 2 лет назад

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.

CVSS3: 8.6
github
около 2 лет назад

Eclipse Parsson stack overflow when parsing deeply nested input

6.8 Medium

CVSS3

Уязвимость CVE-2023-7272