PT-2021-3184 · Gjson · Gjson

Toptotu

·

Published

2021-01-05

·

Updated

2022-08-25

·

CVE-2020-36066

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GJSON versions prior to 1.6.5
Description The issue is related to an uncontrolled resource consumption in the GJSON library, which can be exploited by a remote attacker using a specially crafted JSON request to cause a denial of service. A maliciously crafted JSON input can lead to a denial of service attack.
Recommendations For versions prior to 1.6.5, update to version 1.6.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the GJSON library until a patch is available. Avoid using the GJSON library with untrusted JSON inputs until the issue is resolved.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2021-02869
CVE-2020-36066
GHSA-WJM3-FQ3R-5X46
GO-2022-0957

Affected Products

Gjson