CVE-2021-27568
Summary
| CVE | CVE-2021-27568 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 02:15:00 UTC |
| Updated | 2023-11-07 03:31:00 UTC |
| Description | An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Uncaught Exception in Parser · Issue #60 · netplex/json-smart-v2 · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Uncaught Exception in Parser · Issue #7 · netplex/json-smart-v1 · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| [druid-commits] 20210712 [GitHub] [druid] zachjsh merged pull request #11438: Suppress CVE-2021-27568 from json-smart 2.3 dependency |
|
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - January 2022 |
MISC |
www.oracle.com |
|
| [druid-commits] 20210712 [druid] branch master updated: Suppress CVE-2021-27568 from json-smart 2.3 dependency (#11438) |
|
lists.apache.org |
|
| [druid-commits] 20210712 [GitHub] [druid] zachjsh opened a new pull request #11438: Suppress CVE-2021-27568 from json-smart 2.3 dependency |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375720 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJUL2021)
- 87478 Oracle WebLogic Server Multiple Vulnerabilities (CPUJAN2022)
- 87489 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2022)
- 981949 Java (maven) Security Update for net.minidev:json-smart-mini (GHSA-v528-7hrm-frqp)