Severity
7.5HIGH
EPSS
0.1%
top 80.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateDec 12

Description

A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Mavennet.minidev:json-smart1.3.01.3.3+1
Debianjson-smart< 2.2-2+deb11u1+3
Ubuntujson-smart< 2.2-2ubuntu0.18.04.1+2

Patches

🔴Vulnerability Details

5
OSV
json-smart vulnerabilities2023-04-12
GHSA
Out of bounds read in json-smart2022-02-10
OSV
Out of bounds read in json-smart2022-02-10
OSV
CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 12021-06-01
CVEList
CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 12021-06-01

📋Vendor Advisories

6
Atlassian
CVE-2021-31684: All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.02023-12-12
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (json-smart) — CVE-2021-316842023-04-15
Ubuntu
Json-smart vulnerabilities2023-04-12
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator (JSON Smart) — CVE-2021-316842022-07-15
Red Hat
json-smart: Denial of Service in JSONParserByteArray function2021-06-01
CVE-2021-31684 (HIGH CVSS 7.5) | A vulnerability was discovered in t | cvebase.io