HIGH7.5
GHSA-8vrw-m3j9-j27c
Denial of Service in jsonparser
Quick fix
GHSA-8vrw-m3j9-j27c — github.com/buger/jsonparser: upgrade to the fixed version with the command below.
go get github.com/buger/jsonparser@v1.1.1Details
jsonparser before 1.1.1 allows attackers to cause a denial of service via a GET call.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/buger/jsonparser
Introduced in:
0Fixed in: 1.1.1Fix
go get github.com/buger/jsonparser@v1.1.1References
- https://nvd.nist.gov/vuln/detail/CVE-2020-35381[ADVISORY]
- https://github.com/buger/jsonparser/issues/219[WEB]
- https://github.com/buger/jsonparser/pull/221[WEB]
- https://github.com/buger/jsonparser/commit/df3ea76ece10095374fd1c9a22a4fb85a44efc42[WEB]
- https://github.com/buger/jsonparser[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27EA7OGCELV7QFAGVIHODHWKMKGFVIUZ[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LJO5N7YTDEUSTKYTNA372CE6VHCZJWUG[WEB]
- https://pkg.go.dev/vuln/GO-2021-0057[WEB]