Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-1370 CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion') #137

Closed
Grimoren opened this issue Mar 21, 2023 · 4 comments

Comments

@Grimoren
Copy link
Contributor

Grimoren commented Mar 21, 2023

This one was published 14 March 2023

Published Vulnerabilities
CVE-2023-1370 (OSSINDEX) suppress

json-smart - Denial of Service (DoS)
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')

CVSSv2:
Base Score: HIGH (7.5)
Vector: /AV:N/AC:L/Au:/C:N/I:N/A:H

References:
OSSINDEX - [CVE-2023-1370] CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')
OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1370
OSSIndex - https://ubuntu.com/security/CVE-2023-1370
Vulnerable Software & Versions (OSSINDEX):

cpe:2.3:a:net.minidev:json-smart:2.4.8:*:*:*:*:*:*:*

Not sure if it's been fixed in the latest(2.4.10), but I see no reference the CVE on the repo

@Grimoren
Copy link
Contributor Author

Apparently this was already complete for 2.4.9

@UrielCh
Copy link
Contributor

UrielCh commented Mar 22, 2023

yep... but 2.4.9 introduce a new bug, so skip v2.4.9 and use directly the v2.4.10

@apryamostanov
Copy link

I seen this warning in IntelliJ Idea and came here.

I do not understand how "crash" software is a vulnerability.

@UrielCh
Copy link
Contributor

UrielCh commented Jun 12, 2023

It's more of a potential DDOS helper.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants