7.5

CVE-2024-21907

Exploit

Improper Handling of Exceptional Conditions in Newtonsoft.Json

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NewtonsoftJson.Net Version < 13.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 32.91% 0.981
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

https://alephsecurity.com/2018/10/22/StackOverflowException/
Exploit
https://alephsecurity.com/vulns/aleph-2018004
Exploit
https://github.com/JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66
Patch
https://github.com/JamesNK/Newtonsoft.Json/issues/2457
Third Party Advisory
Exploit
Issue Tracking
https://github.com/JamesNK/Newtonsoft.Json/pull/2462
Patch
https://github.com/advisories/GHSA-5crp-9r3c-p9vr
Third Party Advisory
https://security.snyk.io/vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678
Third Party Advisory
Exploit
https://vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vr
Third Party Advisory