HIGH7.5
GHSA-3vqj-43w4-2q58
json stack overflow vulnerability
Quick fix
GHSA-3vqj-43w4-2q58 — cn.hutool:hutool-json: upgrade to the fixed version with the command below.
# pom.xml: bump <version>5.8.25</version> for cn.hutool:hutool-jsonDetails
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 and org.json:json before version 20230227 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/cn.hutool:hutool-json
Introduced in:
0Fixed in: 5.8.25Fix
# pom.xml: bump <version>5.8.25</version> for cn.hutool:hutool-jsonMaven/org.json:json
Introduced in:
0Fixed in: 20230227Fix
# pom.xml: bump <version>20230227</version> for org.json:jsonReferences
- https://nvd.nist.gov/vuln/detail/CVE-2022-45688[ADVISORY]
- https://github.com/dromara/hutool/issues/2748[WEB]
- https://github.com/stleary/JSON-java/issues/708[WEB]
- https://github.com/dromara/hutool/commit/6a2b585de0a380e8c12016dbaa1620b69be11b8c[WEB]
- https://github.com/stleary/JSON-java/commit/a6e412bded7a0ad605adfeca029318f184c32102[WEB]
- https://github.com/dromara/hutool/releases/tag/5.8.25[WEB]