vulnerability

Amazon Linux 2023: CVE-2024-23337: Medium priority package update for jq

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
May 21, 2025
Added
Jul 30, 2025
Modified
Jul 30, 2025

Description

A denial-of-service vulnerability has been identified in jq, the command-line JSON processor, affecting versions up to and including 1.7.1. This flaw stems from an integer overflow that occurs when attempting to assign a value using an array index of 2147483647 (the maximum value for a 32-bit signed integer). Exploiting this condition can lead to a denial-of-service, rendering the jq process unusable.

Solutions

amazon-linux-2023-upgrade-jqamazon-linux-2023-upgrade-jq-debuginfoamazon-linux-2023-upgrade-jq-debugsourceamazon-linux-2023-upgrade-jq-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.