HIGHMaven →
json-smart Uncontrolled Recursion vulnerability
json-smart Uncontrolled Recursion vulnerability
Affected packages
- net.minidev:json-smart— before 2.4.9
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 1.12%
- EPSS percentile
- 63.0%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 63%.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2023-1370
- https://github.com/netplex/json-smart-v2/issues/137
- https://github.com/netplex/json-smart-v2/commit/5b3205d051952d3100aa0db1535f6ba6226bd87a
- https://github.com/netplex/json-smart-v2/commit/e2791ae506a57491bc856b439d706c81e45adcf8
- https://github.com/oswaldobapvicjr/jsonmerge
- https://research.jfrog.com/vulnerabilities/stack-exhaustion-in-json-smart-leads-to-denial-of-service-when-parsing-malformed-json-xray-427633
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://security.snyk.io/vuln/SNYK-JAVA-NETMINIDEV-3369748
- https://www.cve.org/CVERecord?id=CVE-2023-1370
Structured record: https://osv.dev/vulnerability/GHSA-493p-pfq6-5258
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta