VDB
Sign up
HIGH7.5

GHSA-3vqj-43w4-2q58

json stack overflow vulnerability

Quick fix

GHSA-3vqj-43w4-2q58 — cn.hutool:hutool-json: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.8.25</version> for cn.hutool:hutool-json

Details

A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 and org.json:json before version 20230227 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/cn.hutool:hutool-json
Introduced in: 0Fixed in: 5.8.25
Fix# pom.xml: bump <version>5.8.25</version> for cn.hutool:hutool-json
Maven/org.json:json
Introduced in: 0Fixed in: 20230227
Fix# pom.xml: bump <version>20230227</version> for org.json:json

References