PT-2021-7478 · Unknown+4 · Json Smart+5

Published

2021-04-16

·

Updated

2024-06-21

·

CVE-2021-31684

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions JSON Smart versions prior to 1.3.3 and 2.4.5
Description A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart, which causes a denial of service (DOS) via a crafted web request. The issue is related to a buffer overflow in memory, allowing a remote attacker to cause a denial of service by sending specially crafted web requests.
Recommendations For versions prior to 1.3.3, update to version 1.3.3 or later. For versions prior to 2.4.5, update to version 2.4.5 or later. As a temporary workaround, consider disabling the indexOf function in JSONParserByteArray until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06727
CVE-2021-31684
DLA-3373-1
GHSA-FG2V-W576-W4V3
USN-6011-1

Affected Products

Astra Linux
Confluence
Json Smart
Jira Service Management Server
Linuxmint
Ubuntu