7.5

CVE-2023-5072

Exploit

DoS Vulnerability in JSON-Java

Denial of Service  in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StlearyJson-java Version <= 20230618
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.45% 0.699
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve-coordination@google.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://security.netapp.com/advisory/ntap-20240621-0007/
http://www.openwall.com/lists/oss-security/2023/12/13/4
https://github.com/stleary/JSON-java/issues/758
Issue Tracking
https://github.com/stleary/JSON-java/issues/771
Exploit
Issue Tracking