PT-2021-23565 · Gjson · Gjson

Published

2021-10-25

·

Updated

2024-05-02

·

CVE-2021-42248

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GJSON versions 1.9.2 and earlier GJSON version 1.9.3 is not affected, but versions prior to 1.9.3 are vulnerable, so the correct consolidation is: GJSON versions prior to 1.9.3
Description The issue allows attackers to cause a ReDoS (regular expression denial of service) attack via crafted JSON input. A maliciously crafted path can cause Get and other query functions to consume excessive amounts of CPU and time.
Recommendations For GJSON versions prior to 1.9.3, update to version 1.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the input to the Get and other query functions to prevent excessive CPU and time consumption.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-42248
GHSA-C9GM-7RFJ-8W5H
GHSA-PPJ4-34RQ-V8J9
GO-2021-0265
GO-2022-0592

Affected Products

Gjson