PT-2023-28307 · Hutool · Hutool
Changxiaoning
·
Published
2023-09-08
·
Updated
2023-09-13
·
CVE-2023-42278
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
hutool version 5.8.21
Description
The issue is related to a buffer overflow in the
JSONUtil.parse() component.Recommendations
For hutool version 5.8.21, consider disabling the
JSONUtil.parse() function until a patch is available. Restrict the use of this component to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hutool