-
-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2023-1370 CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion') #137
Comments
Apparently this was already complete for 2.4.9 |
yep... but 2.4.9 introduce a new bug, so skip v2.4.9 and use directly the v2.4.10 |
I seen this warning in IntelliJ Idea and came here. I do not understand how "crash" software is a vulnerability. |
It's more of a potential DDOS helper. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This one was published 14 March 2023
Published Vulnerabilities
CVE-2023-1370 (OSSINDEX) suppress
json-smart - Denial of Service (DoS)
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: HIGH (7.5)
Vector: /AV:N/AC:L/Au:/C:N/I:N/A:H
References:
OSSINDEX - [CVE-2023-1370] CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')
OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1370
OSSIndex - https://ubuntu.com/security/CVE-2023-1370
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:net.minidev:json-smart:2.4.8:*:*:*:*:*:*:*
Not sure if it's been fixed in the latest(2.4.10), but I see no reference the CVE on the repo
The text was updated successfully, but these errors were encountered: