Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47855

Опубликовано: 04 окт. 2024
Источник: redhat
CVSS3: 5.3

Описание

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

A flaw was found in JSON-lib's JSONTokener component. This vulnerability allows a denial of service via an unbalanced comment string.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftorg.elasticsearch.plugin.prometheus-prometheus-exporterFix deferred
Red Hat Data Grid 8net.sf.json-lib/json-libWill not fix
Red Hat Fuse 7net.sf.json-lib/json-libOut of support scope
Red Hat JBoss Data Grid 7net.sf.json-lib/json-libOut of support scope
Red Hat JBoss Enterprise Application Platform 7net.sf.json-lib/json-libOut of support scope
Red Hat JBoss Enterprise Application Platform 8net.sf.json-lib/json-libNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packnet.sf.json-lib/json-libNot affected
Red Hat Single Sign-On 7net.sf.json-lib/json-libFix deferred
streams for Apache Kafkanet.sf.json-lib/json-libOut of support scope
OCP-Tools-4.12-RHEL-8jenkinsFixedRHSA-2025:222304.03.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2316421json-lib: Mishandling of an unbalanced comment string in json-lib

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

CVSS3: 5.3
nvd
около 1 года назад

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

CVSS3: 5.3
debian
около 1 года назад

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalance ...

suse-cvrf
около 1 года назад

Security update for json-lib

CVSS3: 5.3
redos
около 1 месяца назад

Уязвимость JSON-lib

5.3 Medium

CVSS3