CVE-2018-18854: High severity spray-json vulnerability
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18854?
The severity of CVE-2018-18854 is high with a severity value of 7.5.
How does CVE-2018-18854 affect Lightbend Spray spray-json?
CVE-2018-18854 affects Lightbend Spray spray-json through version 1.3.4.
What can remote attackers do with CVE-2018-18854?
Remote attackers can cause a denial of service (resource consumption) by exploiting the vulnerability.
What is the cause of the denial of service in CVE-2018-18854?
The denial of service in CVE-2018-18854 is caused by Algorithmic Complexity during the parsing of many JSON object fields with keys that have the same hash code.
Is there a fix available for CVE-2018-18854?
Yes, it is recommended to update to a version of Lightbend Spray spray-json that is not affected by the vulnerability.