Skip to content

🔐 CVE-2023-4043: pkg:maven/org.eclipse.parsson/parsson@1.1.0 #496

@github-actions

Description

@github-actions

Summary

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.

To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

CVE: CVE-2023-4043
CWE: CWE-20

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity related change

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions