PT-2021-6276 · Netplex · Netplex Json-Smart-V2+1
Published
2021-02-23
·
Updated
2023-02-15
·
CVE-2021-27568
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
netplex json-smart-v1 versions through 2015-10-23
netplex json-smart-v2 versions through 2.4
Description
An issue was discovered where an exception is thrown from a function but not caught, as demonstrated by
NumberFormatException. This may cause programs using the library to crash or expose sensitive information. The vulnerability is related to insufficient checking of unusual or exceptional states, which could allow a remote attacker to cause the application to crash or disclose protected information.Recommendations
For netplex json-smart-v1 versions through 2015-10-23, consider updating to a version after 2015-10-23 to resolve the issue.
For netplex json-smart-v2 versions through 2.4, consider updating to a version after 2.4 to resolve the issue.
As a temporary workaround, consider implementing exception handling for
NumberFormatException to prevent program crashes and information exposure.Exploit
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netplex Json-Smart-V1
Netplex Json-Smart-V2