CVE-2020-36067: Out-of-bounds Read
Published Jan 5, 2021
·Updated
GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.
Affected Software
1 affected component
Gjson Project Gjson<=1.6.5
Event History
Jan 5, 2021
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36067.
2
What is the title of this vulnerability?
The title of this vulnerability is 'GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range)'.
3
What is the severity of CVE-2020-36067?
The severity of CVE-2020-36067 is high with a severity value of 7.5.
4
How does the vulnerability CVE-2020-36067 affect GJSON?
The vulnerability CVE-2020-36067 affects GJSON version 1.6.5 and allows attackers to cause a denial of service through a crafted GET call resulting in a runtime error: slice bounds out of range panic.
5
Is there a fix available for CVE-2020-36067?
At the moment, there is no known fix available for CVE-2020-36067. It is advised to update to a newer version of GJSON when a fix is released.