GHSA-8j28-34qq-gmch

Suggest an improvement
Source
https://github.com/advisories/GHSA-8j28-34qq-gmch
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-8j28-34qq-gmch/GHSA-8j28-34qq-gmch.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8j28-34qq-gmch
Aliases
  • CVE-2022-47937
Published
2023-05-15T12:30:16Z
Modified
2024-03-29T14:48:46.905689Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
Details

Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling Commons Johnzon OSGi bundle provided by the Apache Sling project, but may of course use other JSON libraries.

Database specific
{
    "nvd_published_at": "2023-05-15T10:15:10Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-05-15T20:51:20Z"
}
References

Affected packages

Maven / org.apache.sling:org.apache.sling.commons.json

Package

Name
org.apache.sling:org.apache.sling.commons.json
View open source insights on deps.dev
Purl
pkg:maven/org.apache.sling/org.apache.sling.commons.json

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0.20

Affected versions

2.*

2.0.2-incubator
2.0.4-incubator
2.0.6
2.0.8
2.0.10
2.0.12
2.0.16
2.0.18
2.0.20