Out of bounds read in json-smart
High severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Jun 21, 2024
Package
Affected versions
>= 1.3.0, < 1.3.3
>= 2.4.0, < 2.4.4
Patched versions
1.3.3
2.4.4
Description
Published by the National Vulnerability Database
Jun 1, 2021
Reviewed
Jun 2, 2021
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Jun 21, 2024
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions prior to 1.3.3 and 2.4.5 which causes a denial of service (DOS) via a crafted web request.
References