A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade json-smart | Apr 3, 2023 | Jun 1, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 35227385 for version 14.1.1.0.0. | Jul 19, 2023 | Jun 1, 2021 |
| Ubuntu | — | Upgrade libjson-smart-java | Apr 17, 2023 | Jun 1, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub