REDHAT-BUG-2256063: Medium severity json-path JsonPath vulnerability
Published Dec 28, 2023
·Updated
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
https://github.com/json-path/JsonPath/issues/973
Affected Software
1 affected component
json-path JsonPath
Event History
Dec 28, 2023
Data Sourced
via Red Hat·06:06 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2256063?
REDHAT-BUG-2256063 is classified as a critical vulnerability due to the potential for a stack overflow.
2
How do I fix REDHAT-BUG-2256063?
To fix REDHAT-BUG-2256063, update to the latest version of json-path that addresses the stack overflow issue.
3
What systems are affected by REDHAT-BUG-2256063?
REDHAT-BUG-2256063 affects versions of json-path prior to v2.8.0.
4
What kind of vulnerability is REDHAT-BUG-2256063?
REDHAT-BUG-2256063 is a stack overflow vulnerability found in the Criteria.parse() method.
5
What can happen if REDHAT-BUG-2256063 is exploited?
If REDHAT-BUG-2256063 is exploited, it may lead to application crashes or arbitrary code execution.