[MAVEN:GHSA-3VQJ-43W4-2Q58] json stack overflow vulnerability

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 and org.json:json before version 20230227 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

Package Affected Version
pkg:maven/org.json/json < 20230227
pkg:maven/cn.hutool/hutool-json <= 5.8.10
Package Fixed Version
pkg:maven/org.json/json = 20230227
pkg:maven/cn.hutool/hutool-json = 5.8.25
ID
MAVEN:GHSA-3VQJ-43W4-2Q58
Severity
high
URL
https://github.com/advisories/GHSA-3vqj-43w4-2q58
Published
2022-12-13T15:30:26
(21 months ago)
Modified
2023-04-14T17:02:26
(17 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.json/json org.json json < 20230227
Fixed pkg:maven/org.json/json org.json json = 20230227
Affected pkg:maven/cn.hutool/hutool-json cn.hutool hutool-json <= 5.8.10
Fixed pkg:maven/cn.hutool/hutool-json cn.hutool hutool-json = 5.8.25
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...