First published: Wed Oct 31 2018(Updated: )
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lightbend Spray-json | <=1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Lightbend Spray spray-json is CVE-2018-18853.
CVE-2018-18853 has a severity level of high (7.5).
CVE-2018-18853 allows remote attackers to cause a denial of service (resource consumption) due to Algorithmic Complexity during the parsing of a field with many decimal digits.
Lightbend Spray spray-json up to and including version 1.3.4 is affected by CVE-2018-18853.
At the moment, there is no known fix for CVE-2018-18853. It is recommended to follow the recommendations provided by the vendor or product developers.