PT-2021-7478 · Unknown+4 · Json Smart+5
Published
2021-04-16
·
Updated
2024-06-21
·
CVE-2021-31684
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
JSON Smart versions prior to 1.3.3 and 2.4.5
Description
A vulnerability was discovered in the
indexOf function of JSONParserByteArray in JSON Smart, which causes a denial of service (DOS) via a crafted web request. The issue is related to a buffer overflow in memory, allowing a remote attacker to cause a denial of service by sending specially crafted web requests.Recommendations
For versions prior to 1.3.3, update to version 1.3.3 or later.
For versions prior to 2.4.5, update to version 2.4.5 or later.
As a temporary workaround, consider disabling the
indexOf function in JSONParserByteArray until a patch is available.Exploit
Fix
DoS
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Confluence
Json Smart
Jira Service Management Server
Linuxmint
Ubuntu