CVE-2021-27568
published 2021-02-23CVE-2021-27568: An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.89%
85.3th percentile
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| json-smart_project | json-smart-v1 | < 1.3.2 | 1.3.2 |
| json-smart_project | json-smart-v2 | < 2.3.1 | 2.3.1 |
| json-smart_project | json-smart-v2 | >= 2.4 < 2.4.1 | 2.4.1 |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | oss_support_tools | < 2.12.42 | 2.12.42 |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_oracle9.1MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: BI Application Archive (json-smart) — CVE-2021-27568
vendor_oracle·2023-04-15·CVSS 5.3
CVE-2021-27568 [MEDIUM] Oracle Oracle Analytics Risk Matrix: BI Application Archive (json-smart) — CVE-2021-27568
Oracle Oracle Analytics Risk Matrix: BI Application Archive (json-smart) vulnerability
CVE: CVE-2021-27568
CVSS: 5.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (netplex json-smart) — CVE-2021-27568
vendor_oracle·2022-01-15·CVSS 9.1
CVE-2021-27568 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (netplex json-smart) — CVE-2021-27568
Oracle Oracle Communications Risk Matrix: Policy (netplex json-smart) vulnerability
CVE: CVE-2021-27568
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: REST Services (netplex json-smart-v1) — CVE-2021-27568
vendor_oracle·2021-07-15·CVSS 9.1
CVE-2021-27568 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: REST Services (netplex json-smart-v1) — CVE-2021-27568
Oracle Oracle PeopleSoft Risk Matrix: REST Services (netplex json-smart-v1) vulnerability
CVE: CVE-2021-27568
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
json-smart: uncaught exception may lead to crash or information disclosure
vendor_redhat·2021-02-23·CVSS 5.9
CVE-2021-27568 [MEDIUM] CWE-200 json-smart: uncaught exception may lead to crash or information disclosure
json-smart: uncaught exception may lead to crash or information disclosure
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
A flaw was found in json-smart. When an exception is thrown from a function, but is not caught, the program using the library may crash or expose sensitive information. The highest threat from this vulnerability is to data confidentiality and system availability.
In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of json-smar
GHSA
Improper Check for Unusual or Exceptional Conditions in json-smart
ghsa·2021-06-16
CVE-2021-27568 [MEDIUM] CWE-754 Improper Check for Unusual or Exceptional Conditions in json-smart
Improper Check for Unusual or Exceptional Conditions in json-smart
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
OSV
Improper Check for Unusual or Exceptional Conditions in json-smart
osv·2021-06-16
CVE-2021-27568 [MEDIUM] Improper Check for Unusual or Exceptional Conditions in json-smart
Improper Check for Unusual or Exceptional Conditions in json-smart
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosure
bugzilla·2021-03-17·CVSS 5.9
CVE-2021-27568 [MEDIUM] CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosure
CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosure
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
Upstream Reference:
https://github.com/netplex/json-smart-v1/issues/7
https://github.com/netplex/json-smart-v2/issues/60
Discussion:
A word on scoring, our scoring is currently 9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H and NVD of 9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H will change to 5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
My take:
Exploitability Metrics:
Attack Vect
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
https://github.com/netplex/json-smart-v1/issues/7https://github.com/netplex/json-smart-v2/issues/60https://lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://github.com/netplex/json-smart-v1/issues/7https://github.com/netplex/json-smart-v2/issues/60https://lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-02-23
Published