Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-5072 - Vulnerability with hawtio #2958

Closed
sasikumar-ms7 opened this issue Oct 17, 2023 · 5 comments · Fixed by #2972
Closed

CVE-2023-5072 - Vulnerability with hawtio #2958

sasikumar-ms7 opened this issue Oct 17, 2023 · 5 comments · Fixed by #2972
Assignees

Comments

@sasikumar-ms7
Copy link

sasikumar-ms7 commented Oct 17, 2023

New vulnerability CVE-2023-5072 is identified with latest stable version of hawtio 2.17.6. This vulnerability is from org.json:json-20230227. Please upgrade to json:20231013 to fix this vulnerability.

Error details as follows
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

@tadayosi
Copy link
Member

@mmelko Could you have a look?

@jbertram
Copy link
Contributor

Any update on this? I'm looking to get this fixed in ActiveMQ Artemis.

@mmelko
Copy link
Contributor

mmelko commented Nov 6, 2023

3.x: #2972
4.x: #2971
main: #2970

@jbertram
Copy link
Contributor

jbertram commented Nov 6, 2023

ActiveMQ Artemis is currently using 2.17.6. Will there be a 2.17.7 release with this fix?

@tadayosi tadayosi linked a pull request Nov 7, 2023 that will close this issue
@tadayosi
Copy link
Member

tadayosi commented Nov 7, 2023

@jbertram Releasing 2.17.7 soon.

@tadayosi tadayosi closed this as completed Nov 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants