Affected packages
- github.com/hjson/hjson-go/v4
- laktak/hjson— before 2.3.0
- org.hjson:hjson— before 3.0.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2023-34620
- https://github.com/hjson/hjson-java/issues/24
- https://github.com/hjson/hjson-cpp/pull/54
- https://github.com/hjson/hjson-go/pull/67
- https://github.com/hjson/hjson-php/pull/45
- https://github.com/hjson/hjson-go/commit/326599cebc6ef759892f473bf1439b98466a99fa
- https://github.com/hjson/hjson-php/commit/2d1b8b4b158a8d841f3a228f267c7cd84fe5a4fa
Structured record: https://osv.dev/vulnerability/GHSA-5wfc-hjrc-gq87
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta