Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3588

Опубликовано: 14 апр. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of the component JSON File Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

A flaw was found in jsonschema2pojo, specifically in the apply function within SchemaRule.java. The issue leads to a stack-based buffer overflow, requiring local system access for exploitation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apicurio Registry 2jsonschema2pojo-coreFix deferred
Red Hat build of Apicurio Registry 3jsonschema2pojo-coreFix deferred
Red Hat Fuse 7jsonschema2pojo-coreFix deferred
Red Hat Fuse 7jsonschema2pojo-maven-pluginFix deferred
Red Hat Fuse 7jsonschema2pojo-scalagenFix deferred
Red Hat JBoss Enterprise Application Platform 8jsonschema2pojo-coreFix deferred
Red Hat JBoss Enterprise Application Platform 8jsonschema2pojo-gradle-pluginFix deferred
Red Hat JBoss Enterprise Application Platform 8jsonschema2pojo-maven-pluginFix deferred
Red Hat JBoss Enterprise Application Platform 8kubernetes-model-jsonschema2pojoFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packjsonschema2pojo-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2359604jsonschema2pojo: joelittlejohn jsonschema2pojo JSON File SchemaRule.java apply stack-based overflow

EPSS

Процентиль: 1%
0.00013
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of the component JSON File Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
github
5 месяцев назад

jsonschema2pojo has Improper Restriction of Operations within the Bounds of a Memory Buffer

EPSS

Процентиль: 1%
0.00013
Низкий

5.3 Medium

CVSS3