VulnerabilityModified
CVE-2021-31684
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
HIGH 7.5EPSS 2.30%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- json-smart project/json-smart-v1 · json-smart project/json-smart-v2 · oracle/utilities framework
- Source
- cve@mitre.org
References
- https://github.com/netplex/json-smart-v1/issues/10Issue Tracking, Third Party Advisory
- https://github.com/netplex/json-smart-v1/pull/11Patch, Third Party Advisory
- https://github.com/netplex/json-smart-v2/issues/67Exploit, Issue Tracking, Third Party Advisory
- https://github.com/netplex/json-smart-v2/pull/68Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00030.html
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://github.com/netplex/json-smart-v1/issues/10Issue Tracking, Third Party Advisory
- https://github.com/netplex/json-smart-v1/pull/11Patch, Third Party Advisory
- https://github.com/netplex/json-smart-v2/issues/67Exploit, Issue Tracking, Third Party Advisory
- https://github.com/netplex/json-smart-v2/pull/68Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00030.html
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.