was withdrawn by its CNA. Further investigation showed that it was not a security issue.
All versions of package com.jsoniter:jsoniter are vulnerable to Deserialization of Untrusted Data via malicious JSON strings. This may lead to a Denial of Service, and in certain cases, code execution.
{
"cwe_ids": [
"CWE-502"
],
"github_reviewed": true,
"github_reviewed_at": "2021-09-20T20:25:57Z",
"nvd_published_at": "2021-09-19T14:15:00Z",
"severity": "HIGH"
}