First published: Tue Dec 13 2022(Updated: )
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hutool Hutool | =5.8.10 | |
Json-java Project Json-java | <20230227 | |
IBM Cloud Pak for Business Automation | <=V22.0.2 - V22.0.2-IF004 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF020 | |
IBM Cloud Pak for Business Automation | <=V22.0.1 - V22.0.1-IF006 and later fixesV21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes | |
maven/cn.hutool:hutool-json | <5.8.25 | 5.8.25 |
maven/org.json:json | <20230227 | 20230227 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45688 is a vulnerability in the XML.toJSONObject component of hutool-json v5.8.10 that allows attackers to cause a denial of service by exploiting a stack-based buffer overflow.
CVE-2022-45688 has a severity rating of 7.5 (High).
Hutool v5.8.10 and Json-java Project v20230227 are affected by CVE-2022-45688.
An attacker can exploit CVE-2022-45688 by sending a specially crafted request to the vulnerable application, causing a stack-based buffer overflow and crashing the application.
Yes, you can find references for CVE-2022-45688 at the following links: [Link 1](https://github.com/dromara/hutool/issues/2748), [Link 2](https://github.com/stleary/JSON-java/issues/708), [Link 3](https://exchange.xforce.ibmcloud.com/vulnerabilities/242881).