GHSA-779h-3r69-4f5p

Suggest an improvement
Source
https://github.com/advisories/GHSA-779h-3r69-4f5p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-779h-3r69-4f5p/GHSA-779h-3r69-4f5p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-779h-3r69-4f5p
Aliases
Published
2023-06-14T15:30:38Z
Modified
2024-11-08T17:22:24.665388Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
json-io vulnerable to stack exhaustion
Details

An issue was discovered json-io through 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that have deeply nested structures.

Database specific
{
    "nvd_published_at": "2023-06-14T14:15:09Z",
    "cwe_ids": [
        "CWE-400",
        "CWE-787"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-06-14T21:04:22Z"
}
References

Affected packages

Maven / com.cedarsoftware:json-io

Package

Name
com.cedarsoftware:json-io
View open source insights on deps.dev
Purl
pkg:maven/com.cedarsoftware/json-io

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14.1

Affected versions

2.*

2.2.25
2.2.29
2.2.30
2.2.31
2.2.32
2.2.33
2.2.34
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.3
2.9.4

3.*

3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2

4.*

4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
4.1.10
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
4.9.5
4.9.6
4.9.7
4.9.8
4.9.9
4.9.10
4.9.11
4.9.12
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.14.0