Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43273
HistorySep 14, 2023 - 5:57 a.m.

Buffer Overflow

2023-09-1405:57:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
buffer overflow
json validation
heap overflow
application crash
security vulnerability
json input

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

27.9%

cn.hutool, hutool-json is vulnerable to Buffer Overflow. The vulnerability is caused by missing validation for JSON input passed to the JSONUtil.parse() method. An attacker can cause a heap buffer overflow by sending a specially crafted JSON string leading to an application crash or unexpected behavior.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

27.9%