First published: Tue Feb 13 2024(Updated: )
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libcpanel-json-xs-perl | <=4.09-1<=4.25-1 | 4.35-1 4.37-1 |
ubuntu/libcpanel-json-xs-perl | <4.19-1ubuntu0.1 | 4.19-1ubuntu0.1 |
ubuntu/libcpanel-json-xs-perl | <4.27-1ubuntu0.1 | 4.27-1ubuntu0.1 |
ubuntu/libcpanel-json-xs-perl | <4.35-1 | 4.35-1 |
cPanel | <4.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48623 has been classified as a high severity vulnerability due to the potential for information disclosure and denial of service.
To fix CVE-2022-48623, upgrade the Cpanel::JSON::XS package to version 4.33 or later for the affected systems.
CVE-2022-48623 affects the Cpanel::JSON::XS package for Perl, specifically versions prior to 4.33.
CVE-2022-48623 can lead to sensitive information leakage and may also cause a denial of service.
The affected package Cpanel::JSON::XS is maintained by Rurban.