CVE-2023-31441: Null Pointer Dereference
In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafted JSON file to sanitizeJson and cause an exception. This is related to the U+FFFD Unicode replacement character. A for loop does not consider that a data structure is being modified during loop execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31441?
CVE-2023-31441 is classified as a high severity vulnerability due to the potential for unauthorized access and system disruption.
How do I fix CVE-2023-31441?
To fix CVE-2023-31441, upgrade to version 3.3.1 or later of the affected Advisor Network software.
What versions of the software are affected by CVE-2023-31441?
CVE-2023-31441 affects Advisor Network versions up to and including 3.3.0.
What is the impact of exploiting CVE-2023-31441?
Exploiting CVE-2023-31441 can lead to application exceptions caused by crafted JSON inputs, potentially disrupting services.
Who is affected by CVE-2023-31441?
Organizations using the Advisor Network software version 3.3.0 or earlier are affected by CVE-2023-31441.