First published: Wed Oct 31 2018(Updated: )
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lightbend Spray-json | <=1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18854 is high with a severity value of 7.5.
CVE-2018-18854 affects Lightbend Spray spray-json through version 1.3.4.
Remote attackers can cause a denial of service (resource consumption) by exploiting the vulnerability.
The denial of service in CVE-2018-18854 is caused by Algorithmic Complexity during the parsing of many JSON object fields with keys that have the same hash code.
Yes, it is recommended to update to a version of Lightbend Spray spray-json that is not affected by the vulnerability.