[MAVEN:GHSA-Q8XJ-8XG3-W432] Uncontrolled Resource Consumption in spray-json

Severity High
Affected Packages 3
Fixed Packages 3
CVEs 1

Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).

ID
MAVEN:GHSA-Q8XJ-8XG3-W432
Severity
high
URL
https://github.com/advisories/GHSA-q8xj-8xg3-w432
Published
2018-11-09T17:41:35
(5 years ago)
Modified
2023-01-09T05:04:19
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.spray/spray-json_2.12 io.spray spray-json_2.12 < 1.3.5
Fixed pkg:maven/io.spray/spray-json_2.12 io.spray spray-json_2.12 = 1.3.5
Affected pkg:maven/io.spray/spray-json_2.11 io.spray spray-json_2.11 < 1.3.5
Fixed pkg:maven/io.spray/spray-json_2.11 io.spray spray-json_2.11 = 1.3.5
Affected pkg:maven/io.spray/spray-json_2.10 io.spray spray-json_2.10 < 1.3.5
Fixed pkg:maven/io.spray/spray-json_2.10 io.spray spray-json_2.10 = 1.3.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...