CVE-2023-51074: Buffer Overflow
json-path is vulnerable to a denial of service, caused by a stack-based buffer overflow in the Criteria.parse method. By sending a specially crafted input, a remote attacker could exploit this vulnerability to cause an uncontrolled recursion, and results in a denial of service condition.
Other sources
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
— GitHub
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.jayway.jsonpath:json-pathto a version that resolves this vulnerability.Fixed in 2.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51074?
CVE-2023-51074 is classified as a denial of service vulnerability due to a stack-based buffer overflow.
How do I fix CVE-2023-51074?
To remediate CVE-2023-51074, upgrade json-path to version 2.9.0 or later.
Which versions of json-path are affected by CVE-2023-51074?
CVE-2023-51074 affects json-path versions up to 2.8.0.
Can CVE-2023-51074 be exploited remotely?
Yes, a remote attacker can exploit CVE-2023-51074 by sending specially crafted input.
Which software products are impacted by CVE-2023-51074?
CVE-2023-51074 impacts json-path and products like IBM Cognos Analytics versions up to 12.0.3.