PT-2024-32854 · Json Lib+3 · Json-Lib+3

Published

2024-10-03

·

Updated

2025-10-28

·

CVE-2024-47855

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions JSON-lib versions prior to 3.1.0
Description The issue is related to the handling of an unbalanced comment string in the util/JSONTokener.java file. This flaw can be exploited due to the mishandling of such strings.
Recommendations For versions prior to 3.1.0, update to version 3.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the util/JSONTokener.java file until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-13819
CVE-2024-47855
GHSA-WWCP-26WC-3FXM
OESA-2024-2228
OPENSUSE-SU-2024_3543-1
RHSA-2025:2218
RHSA-2025:2219
RHSA-2025:2220
RHSA-2025:2221
RHSA-2025:2222
RHSA-2025:2223
SUSE-SU-2024:3543-1

Affected Products

Debian
Json-Lib
Red Os
Suse