A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | atlassian-bitbucket-upgrade-latest | Jun 18, 2025 | Jun 17, 2025 | |
| Atlassian Jira | atlassian-jira-upgrade-latest | May 15, 2025 | Apr 15, 2025 | |
| Oracle Weblogic | oracle-weblogic-jul-2025-cpu-12_2_1_4_0oracle-weblogic-jul-2025-cpu-14_1_1_0_0oracle-weblogic-jul-2025-cpu-14_1_2_0_0 | Jul 16, 2025 | Feb 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub