PT-2021-6276 · Netplex · Netplex Json-Smart-V2+1

Published

2021-02-23

·

Updated

2023-02-15

·

CVE-2021-27568

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions netplex json-smart-v1 versions through 2015-10-23 netplex json-smart-v2 versions through 2.4
Description An issue was discovered where an exception is thrown from a function but not caught, as demonstrated by NumberFormatException. This may cause programs using the library to crash or expose sensitive information. The vulnerability is related to insufficient checking of unusual or exceptional states, which could allow a remote attacker to cause the application to crash or disclose protected information.
Recommendations For netplex json-smart-v1 versions through 2015-10-23, consider updating to a version after 2015-10-23 to resolve the issue. For netplex json-smart-v2 versions through 2.4, consider updating to a version after 2.4 to resolve the issue. As a temporary workaround, consider implementing exception handling for NumberFormatException to prevent program crashes and information exposure.

Exploit

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2022-01228
CVE-2021-27568
GHSA-V528-7HRM-FRQP

Affected Products

Netplex Json-Smart-V1
Netplex Json-Smart-V2