PT-2023-12774 · Json2Xml · Json2Xml

Asteriska001

·

Published

2023-08-22

·

Updated

2023-08-25

·

CVE-2022-25024

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions json2xml versions through 3.12.0
Description The issue allows an error in typecode decoding, enabling a remote attack that can lead to an exception, causing a denial of service.
Recommendations For versions through 3.12.0, consider updating to a version that fixes the typecode decoding error to prevent remote attacks leading to a denial of service.

Exploit

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2022-25024
GHSA-8RJ5-2857-877J
PYSEC-2023-149

Affected Products

Json2Xml