First published: Tue Dec 13 2022(Updated: )
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/cn.hutool:hutool-json | <5.8.25 | 5.8.25 |
maven/org.json:json | <20230227 | 20230227 |
Hutool | =5.8.10 | |
Json-java | <20230227 | |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data | <=2.2 | |
IBM Watson Query with Cloud Pak for Data | <=2.1 | |
IBM Watson Query with Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45688 is a vulnerability in the XML.toJSONObject component of hutool-json v5.8.10 that allows attackers to cause a denial of service by exploiting a stack-based buffer overflow.
CVE-2022-45688 has a severity rating of 7.5 (High).
Hutool v5.8.10 and Json-java Project v20230227 are affected by CVE-2022-45688.
An attacker can exploit CVE-2022-45688 by sending a specially crafted request to the vulnerable application, causing a stack-based buffer overflow and crashing the application.
Yes, you can find references for CVE-2022-45688 at the following links: [Link 1](https://github.com/dromara/hutool/issues/2748), [Link 2](https://github.com/stleary/JSON-java/issues/708), [Link 3](https://exchange.xforce.ibmcloud.com/vulnerabilities/242881).