Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
{ "binaries": [ { "binary_name": "libjenkins-json-java", "binary_version": "2.4-jenkins-3-4" } ] }
{ "binaries": [ { "binary_name": "libjettison-java", "binary_version": "1.2-3ubuntu0.1~esm2" } ] }
{ "binaries": [ { "binary_name": "libjson-java", "binary_version": "2.4-2" } ] }
{ "binaries": [ { "binary_name": "libjenkins-json-java", "binary_version": "2.4-jenkins-3-5" } ] }
{ "binaries": [ { "binary_name": "libjettison-java", "binary_version": "1.4.0-1ubuntu0.18.04.1~esm2" } ] }
{ "binaries": [ { "binary_name": "libjson-java", "binary_version": "2.4-3" } ] }
{ "binaries": [ { "binary_name": "libjettison-java", "binary_version": "1.4.0-1ubuntu0.20.04.1+esm1" } ] }
{ "binaries": [ { "binary_name": "libjenkins-json-java", "binary_version": "2.4-jenkins-3-6" } ] }
{ "binaries": [ { "binary_name": "libjettison-java", "binary_version": "1.4.1-1ubuntu0.22.04.1" } ] }
{ "binaries": [ { "binary_name": "libjson-java", "binary_version": "2.4-3.1" } ] }
{ "binaries": [ { "binary_name": "libjenkins-json-java", "binary_version": "2.4-jenkins-3-7" } ] }
{ "binaries": [ { "binary_name": "libjettison-java", "binary_version": "1.5.4-1" } ] }
{ "binaries": [ { "binary_name": "libjenkins-json-java", "binary_version": "2.4-jenkins-8+dfsg-1" } ] }
{ "binaries": [ { "binary_name": "libjson-java", "binary_version": "3.1.0+dfsg-2" } ] }