QID 981114
QID 981114: Java (maven) Security Update for io.spray:spray-json_2.10 (GHSA-f94m-mqhr-mc29)
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f94m-mqhr-mc29 for updates pertaining to this vulnerability.
Vendor References
- GHSA-f94m-mqhr-mc29 -
github.com/advisories/GHSA-f94m-mqhr-mc29
CVEs related to QID 981114
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f94m-mqhr-mc29 | io.spray:spray-json_2.10 |
|
|
| GHSA-f94m-mqhr-mc29 | io.spray:spray-json_2.11 |
|
|
| GHSA-f94m-mqhr-mc29 | io.spray:spray-json_2.12 |
|