Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-21634

Опубликовано: 03 янв. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in ion-java for applications that use ion-java to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the IonValue model and then invoke certain IonValue methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the IonValue model, results in a StackOverflowError originating from the ion-java library. The patch is included in ion-java 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.

A vulnerability was found in Amazon Ion, an implementation of Ion data notation. Ion-java may be affected by denial of service (DoS) due to issues while deserializing encoded data into IonValue. A maliciously crafted Ion data structure may be processed and cause a StackOverflowError, leaving the application in an unreliable state.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftsoftware.amazon.ion/ion-javaNot affected
Red Hat build of Apache Camel for Spring Boot 3software.amazon.ion/ion-javaNot affected
Red Hat build of Apache Camel for Spring Boot 4software.amazon.ion/ion-javaNot affected
Red Hat Build of Keycloaksoftware.amazon.ion/ion-javaNot affected
Red Hat build of Quarkussoftware.amazon.ion/ion-javaNot affected
Red Hat Fuse 7software.amazon.ion/ion-javaWill not fix
Red Hat Integration Camel K 1software.amazon.ion/ion-javaNot affected
Red Hat JBoss Data Grid 7software.amazon.ion/ion-javaNot affected
Red Hat JBoss Enterprise Application Platform 7ion-javaNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packion-javaNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2304311ion-java: ion-java: Ion Java StackOverflow vulnerability

EPSS

Процентиль: 63%
0.00458
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. The patch is included in `ion-java` 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.

CVSS3: 7.5
github
около 2 лет назад

Ion Java StackOverflow vulnerability

EPSS

Процентиль: 63%
0.00458
Низкий

7.5 High

CVSS3