DoS Vulnerability in JSON-Java
Published Oct 12, 2023
7.5
HIGHCVSS 3.1
EPSS 1.45%
Description
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Affected products
No data.
No data.
RHINT Camel-K 1.10.5
JSON-java
Fixed · RHSA-2024:0148
RHINT Camel-Springboot 3.20.4
JSON-java
Fixed · RHSA-2023:7845
RHINT Camel-Springboot 4.0.2
n/a
Fixed · RHSA-2023:7842
RHPAM 7.13.5 async
JSON-java
Fixed · RHSA-2024:1353
Red Hat AMQ Broker 7
n/a
Fixed · RHSA-2024:3752
Red Hat AMQ Broker 7
hawtio-war
Fixed · RHSA-2024:4271
Red Hat AMQ Broker 7
hawtio-war
Fixed · RHSA-2024:3762
Red Hat AMQ Streams 2.6.0
n/a
Fixed · RHSA-2023:7678
Red Hat Fuse 7.13.0
JSON-java
Fixed · RHSA-2024:3354
Red Hat build of Apache Camel 4 for Quarkus 3
n/a
Fixed · RHSA-2023:7617
OpenShift Serverless
JSON-java
Not affected
Red Hat Ansible Automation Platform 2
JSON-java
Not affected
Red Hat Data Grid 8
JSON-java
Not affected
Red Hat Decision Manager 7
JSON-java
Affected
Red Hat Integration Camel Quarkus 2
JSON-java
Affected
Red Hat JBoss Data Grid 7
JSON-java
Will not fix
Red Hat JBoss Enterprise Application Platform 6
json
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
json
Not affected
Red Hat JBoss Enterprise Application Platform 8
json
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
JSON-java
Not affected
Red Hat JBoss Fuse 6
JSON-java
Out of support scope
Red Hat JBoss Fuse Service Works 6
JSON-java
Out of support scope
Red Hat Single Sign-On 7
JSON-java
Not affected
Red Hat build of Apicurio Registry 2
JSON-java
Affected
Red Hat build of Debezium 2
JSON-java
Not affected
streams for Apache Kafka
JSON-java
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHINT Camel-K 1.10.5 | JSON-java | Fixed | RHSA-2024:0148 |
| RHINT Camel-Springboot 3.20.4 | JSON-java | Fixed | RHSA-2023:7845 |
| RHINT Camel-Springboot 4.0.2 | n/a | Fixed | RHSA-2023:7842 |
| RHPAM 7.13.5 async | JSON-java | Fixed | RHSA-2024:1353 |
| Red Hat AMQ Broker 7 | n/a | Fixed | RHSA-2024:3752 |
| Red Hat AMQ Broker 7 | hawtio-war | Fixed | RHSA-2024:4271 |
| Red Hat AMQ Broker 7 | hawtio-war | Fixed | RHSA-2024:3762 |
| Red Hat AMQ Streams 2.6.0 | n/a | Fixed | RHSA-2023:7678 |
| Red Hat Fuse 7.13.0 | JSON-java | Fixed | RHSA-2024:3354 |
| Red Hat build of Apache Camel 4 for Quarkus 3 | n/a | Fixed | RHSA-2023:7617 |
| OpenShift Serverless | JSON-java | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | JSON-java | Not affected | n/a |
| Red Hat Data Grid 8 | JSON-java | Not affected | n/a |
| Red Hat Decision Manager 7 | JSON-java | Affected | n/a |
| Red Hat Integration Camel Quarkus 2 | JSON-java | Affected | n/a |
| Red Hat JBoss Data Grid 7 | JSON-java | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | json | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | json | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | json | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | JSON-java | Not affected | n/a |
| Red Hat JBoss Fuse 6 | JSON-java | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | JSON-java | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | JSON-java | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | JSON-java | Affected | n/a |
| Red Hat build of Debezium 2 | JSON-java | Not affected | n/a |
| streams for Apache Kafka | JSON-java | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability may cause denial of service with a small string input, causing the server to be unresponsive easily, hence the Important impact.
Red Hat mitigation
No current mitigation is available for this flaw.
References (13)
- http://www.openwall.com/lists/oss-security/2023/12/13/4
- https://access.redhat.com/security/cve/CVE-2023-5072 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2246417 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2880 Advisory
- https://github.com/advisories/GHSA-4jq9-2xhw-jpx7 Advisory
- https://github.com/google/security-research/security/advisories/GHSA-4jq9-2xhw-jpx7
- https://github.com/stleary/JSON-java/commit/60662e2f8384d3449822a3a1179bfe8de67b55bb
- https://github.com/stleary/JSON-java/issues/758 Issue Tracking
- https://github.com/stleary/JSON-java/issues/771 ExploitIssue Tracking
- https://github.com/stleary/JSON-java/pull/759
- https://nvd.nist.gov/vuln/detail/CVE-2023-5072
- https://security.netapp.com/advisory/ntap-20240621-0007/
- https://www.cve.org/CVERecord?id=CVE-2023-5072
Change history (0)
No recorded changes yet.