CVE-2021-31684
published 2021-06-01CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.30%
81.5th percentile
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| debian | json-smart | < json-smart 2.2-2+deb12u1 (bookworm) | json-smart 2.2-2+deb12u1 (bookworm) |
| json-smart | json-smart | >= 0 < 2.2-2+deb11u1 | 2.2-2+deb11u1 |
| json-smart | json-smart | >= 0 < 2.2-2+deb12u1 | 2.2-2+deb12u1 |
| json-smart | json-smart | >= 0 < 2.5.1-1 | 2.5.1-1 |
| json-smart | json-smart | >= 0 < 2.5.1-1 | 2.5.1-1 |
| json-smart | json-smart | >= 0 < 2.2-2ubuntu0.18.04.1 | 2.2-2ubuntu0.18.04.1 |
| json-smart | json-smart | >= 0 < 2.2-2ubuntu0.20.04.1 | 2.2-2ubuntu0.20.04.1 |
| json-smart | json-smart | >= 0 < 2.2-2ubuntu0.22.04.1 | 2.2-2ubuntu0.22.04.1 |
| json-smart_project | json-smart-v1 | >= 1.3 < 1.3.3 | 1.3.3 |
| json-smart_project | json-smart-v2 | >= 2.4 < 2.4.4 | 2.4.4 |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2021-31684: All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
vendor_atlassian·2023-12-12·CVSS 7.5
CVE-2021-31684 [HIGH] CVE-2021-31684: All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
CVE-2021-31684: All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
CVE: CVE-2021-31684
Severity: HIGH
Affected products: Confluence Data Center
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (json-smart) — CVE-2021-31684
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2021-31684 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (json-smart) — CVE-2021-31684
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (json-smart) vulnerability
CVE: CVE-2021-31684
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
Json-smart vulnerabilities
vendor_ubuntu·2023-04-12·CVSS 7.5
CVE-2021-31684 [HIGH] Json-smart vulnerabilities
Title: Json-smart vulnerabilities
Summary: Several security issues were fixed in Json-smart.
It was discovered that Json-smart incorrectly handled memory
when processing input containing unclosed quotes.
A remote attacker could possibly use this issue to cause
applications using Json-smart to crash, leading to a
denial of service. (CVE-2021-31684)
It was discovered that Json-smart incorrectly handled memory
when processing input containing unclosed brackets.
A remote attacker could possibly use this issue to cause
applications using Json-smart to crash, leading to a
denial of service. (CVE-2023-1370)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator (JSON Smart) — CVE-2021-31684
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-31684 [HIGH] Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator (JSON Smart) — CVE-2021-31684
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator (JSON Smart) vulnerability
CVE: CVE-2021-31684
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
json-smart: Denial of Service in JSONParserByteArray function
vendor_redhat·2021-06-01·CVSS 7.5
CVE-2021-31684 [HIGH] CWE-787 json-smart: Denial of Service in JSONParserByteArray function
json-smart: Denial of Service in JSONParserByteArray function
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
A flaw was found in the json-smart package in the JSONParserByteArray. This flaw allows an attacker to cause a denial of service.
Package: json-smart (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: json-smart (Red Hat AMQ Broker 7) - Not affected
Package: json-smart (Red Hat build of Debezium 1) - Not affected
Package: json-smart (Red Hat build of Quarkus) - Affected
Package: json-smart (Red Hat Data Grid 8) - Not affected
Package: json-smart (Red
Debian
CVE-2021-31684: json-smart - A vulnerability was discovered in the indexOf function of JSONParserByteArray in...
vendor_debian·2021·CVSS 7.5
CVE-2021-31684 [HIGH] CVE-2021-31684: json-smart - A vulnerability was discovered in the indexOf function of JSONParserByteArray in...
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
Scope: local
bookworm: resolved (fixed in 2.2-2+deb12u1)
bullseye: resolved (fixed in 2.2-2+deb11u1)
forky: resolved (fixed in 2.5.1-1)
sid: resolved (fixed in 2.5.1-1)
trixie: resolved (fixed in 2.5.1-1)
OSV
json-smart vulnerabilities
osv·2023-04-12·CVSS 7.5
CVE-2021-31684 [HIGH] json-smart vulnerabilities
json-smart vulnerabilities
It was discovered that Json-smart incorrectly handled memory
when processing input containing unclosed quotes.
A remote attacker could possibly use this issue to cause
applications using Json-smart to crash, leading to a
denial of service. (CVE-2021-31684)
It was discovered that Json-smart incorrectly handled memory
when processing input containing unclosed brackets.
A remote attacker could possibly use this issue to cause
applications using Json-smart to crash, leading to a
denial of service. (CVE-2023-1370)
GHSA
Out of bounds read in json-smart
ghsa·2022-02-10
CVE-2021-31684 [HIGH] CWE-125 Out of bounds read in json-smart
Out of bounds read in json-smart
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions prior to 1.3.3 and 2.4.5 which causes a denial of service (DOS) via a crafted web request.
OSV
Out of bounds read in json-smart
osv·2022-02-10
CVE-2021-31684 [HIGH] Out of bounds read in json-smart
Out of bounds read in json-smart
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions prior to 1.3.3 and 2.4.5 which causes a denial of service (DOS) via a crafted web request.
OSV
CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1
osv·2021-06-01·CVSS 7.5
CVE-2021-31684 [HIGH] CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/netplex/json-smart-v1/issues/10https://github.com/netplex/json-smart-v1/pull/11https://github.com/netplex/json-smart-v2/issues/67https://github.com/netplex/json-smart-v2/pull/68https://lists.debian.org/debian-lts-announce/2023/03/msg00030.htmlhttps://security.netapp.com/advisory/ntap-20240621-0006/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/netplex/json-smart-v1/issues/10https://github.com/netplex/json-smart-v1/pull/11https://github.com/netplex/json-smart-v2/issues/67https://github.com/netplex/json-smart-v2/pull/68https://lists.debian.org/debian-lts-announce/2023/03/msg00030.htmlhttps://security.netapp.com/advisory/ntap-20240621-0006/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-06-01
Published