Skip to content

CVE-2023-5072 @ Maven-org.json:json-20090211 #31

@YSLCx

Description

@YSLCx

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2023-5072
Checkmarx Project: YSLCx/Github_demo
Repository URL: https://github.com/YSLCx/Github_demo
Branch: main
Scan ID: f799fc13-25e4-479c-a802-e1aeacbb3e2d


Denial of Service (DoS) in JSON-Java in versions through 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 20231013

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions