[MAVEN:GHSA-Q8XJ-8XG3-W432] Uncontrolled Resource Consumption in spray-json
Severity
High
Affected Packages
3
Fixed Packages
3
CVEs
1
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).
Package | Affected Version |
---|---|
pkg:maven/io.spray/spray-json_2.12 | < 1.3.5 |
pkg:maven/io.spray/spray-json_2.11 | < 1.3.5 |
pkg:maven/io.spray/spray-json_2.10 | < 1.3.5 |
Package | Fixed Version |
---|---|
pkg:maven/io.spray/spray-json_2.12 | = 1.3.5 |
pkg:maven/io.spray/spray-json_2.11 | = 1.3.5 |
pkg:maven/io.spray/spray-json_2.10 | = 1.3.5 |
- ID
- MAVEN:GHSA-Q8XJ-8XG3-W432
- Severity
- high
- URL
- https://github.com/advisories/GHSA-q8xj-8xg3-w432
- Published
-
2018-11-09T17:41:35
(5 years ago) - Modified
-
2023-01-09T05:04:19
(20 months ago) - Rights
- Maven Security Team
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:maven/io.spray/spray-json_2.12 | io.spray | spray-json_2.12 | < 1.3.5 | |||
Fixed | pkg:maven/io.spray/spray-json_2.12 | io.spray | spray-json_2.12 | = 1.3.5 | |||
Affected | pkg:maven/io.spray/spray-json_2.11 | io.spray | spray-json_2.11 | < 1.3.5 | |||
Fixed | pkg:maven/io.spray/spray-json_2.11 | io.spray | spray-json_2.11 | = 1.3.5 | |||
Affected | pkg:maven/io.spray/spray-json_2.10 | io.spray | spray-json_2.10 | < 1.3.5 | |||
Fixed | pkg:maven/io.spray/spray-json_2.10 | io.spray | spray-json_2.10 | = 1.3.5 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |