Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openjdk17Upgrade openjdk21 | Aug 22, 2024 | Oct 12, 2023 |
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Nov 14, 2024 | Jan 16, 2024 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Mar 19, 2024 |
| Debian | — | Upgrade libjson-java | May 15, 2025 | Oct 12, 2023 |
| Oracle Missing Cpu Apr 2024 | — | Apply the April 2024 Critical Patch Update (CPU) for Oracle Database | Apr 25, 2024 | Oct 12, 2023 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 36454290 for version 14.1.1.0.0. | Apr 25, 2024 | Oct 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub