First published: Tue Jan 05 2021(Updated: )
GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gjson Project Gjson | <=1.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-36067.
The title of this vulnerability is 'GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range)'.
The severity of CVE-2020-36067 is high with a severity value of 7.5.
The vulnerability CVE-2020-36067 affects GJSON version 1.6.5 and allows attackers to cause a denial of service through a crafted GET call resulting in a runtime error: slice bounds out of range panic.
At the moment, there is no known fix available for CVE-2020-36067. It is advised to update to a newer version of GJSON when a fix is released.