First published: Tue Feb 23 2021(Updated: )
A flaw was found in json-smart. When an exception is thrown from a function, but is not caught, the program using the library may crash or expose sensitive information. The highest threat from this vulnerability is to data confidentiality and system availability. In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of json-smart package. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Json-smart Project Json-smart-v1 | <1.3.2 | |
Json-smart Project Json-smart-v2 | <2.3.1 | |
Json-smart Project Json-smart-v2 | >=2.4<2.4.1 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle OSS Support Tools | <2.12.42 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
Oracle Utilities Framework | =4.4.0.0.0 | |
Oracle Utilities Framework | =4.4.0.2.0 | |
Oracle Utilities Framework | =4.4.0.3.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
redhat/json-smart | <1.3.2 | 1.3.2 |
redhat/json-smart | <2.4.1 | 2.4.1 |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-27568 is a vulnerability found in json-smart library that can cause program crashes or expose sensitive information when an exception is thrown from a function and not caught.
CVE-2021-27568 has a severity rating of medium with a CVSS score of 5.9.
CVE-2021-27568 affects json-smart-v1 up to 1.3.2 and json-smart-v2 up to 2.4.1.
CVE-2021-27568 can potentially compromise data confidentiality and system availability.
You can find more information about CVE-2021-27568 on the GitHub pages of json-smart-v1 and json-smart-v2, as well as the Red Hat Security Advisory RHSA-2021:3225.