CVE-2021-31684
Summary
| CVE | CVE-2021-31684 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-01 20:15:00 UTC |
| Updated | 2023-03-31 11:15:00 UTC |
| Description | A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3373-1] json-smart security update |
MLIST |
lists.debian.org |
|
| Fix out of bound exception by pcy190 · Pull Request #11 · netplex/json-smart-v1 · GitHub |
MISC |
github.com |
|
| ArrayIndexOutOfBoundsException in parser · Issue #10 · netplex/json-smart-v1 · GitHub |
MISC |
github.com |
|
| Oracle Critical Patch Update Advisory - January 2022 |
MISC |
www.oracle.com |
|
| ArrayIndexOutOfBoundsException in parser · Issue #67 · netplex/json-smart-v2 · GitHub |
MISC |
github.com |
|
| Fix ArrayIndexOutOfBoundsException by pcy190 · Pull Request #68 · netplex/json-smart-v2 · GitHub |
MISC |
github.com |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150676 Oracle WebLogic Server Multiple Vulnerabilities (APR-2023)
- 181646 Debian Security Update for json-smart (DLA 3373-1)
- 199281 Ubuntu Security Notification for Json-smart Vulnerabilities (USN-6011-1)
- 378996 Atlassian Jira Service Management Server and Data Center Denial of Service (DoS) Vulnerability (JSDSERVER-14748)
- 379452 IBM Cognos Analytics Multiple Vulnerabilities (7123154)
- 731024 Atlassian Confluence Data Center and Server Denial of Service (DoS) Vulnerability (CONFSERVER-93361)
- 87542 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2023)