CVE-2021-42248
published 2021-10-25CVE-2021-42248: github.com/tidwall/gjson Vulnerable to REDoS attack GJSON is a Go package that provides a fast and simple way to get values from a json document. GJSON before…
high7.5
github.com/tidwall/gjson Vulnerable to REDoS attack
GJSON is a Go package that provides a fast and simple way to get values from a json document. GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | tidwall_gjson | >= 0 < 1.9.3 | 1.9.3 |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of service via maliciously crafted path in github.com/tidwall/gjson
osv·2022-08-15
CVE-2021-42248 Denial of service via maliciously crafted path in github.com/tidwall/gjson
Denial of service via maliciously crafted path in github.com/tidwall/gjson
A maliciously crafted path can cause Get and other query functions to consume excessive amounts of CPU and time.
OSV
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
osv·2022-05-25
CVE-2021-42248 [HIGH] Duplicate Advisory: ReDoS via crafted JSON input in GJSON
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-ppj4-34rq-v8j9. This link is maintained to preserve external references.
## Original Description
GJSON <= 1.9.2 allows attackers to cause a redos via crafted JSON input.
GHSA
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
ghsa·2022-05-25
CVE-2021-42248 [HIGH] CWE-1333 Duplicate Advisory: ReDoS via crafted JSON input in GJSON
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-ppj4-34rq-v8j9. This link is maintained to preserve external references.
## Original Description
GJSON <= 1.9.2 allows attackers to cause a redos via crafted JSON input.
OSV
github.com/tidwall/gjson Vulnerable to REDoS attack
osv·2021-10-25
CVE-2021-42248 [HIGH] github.com/tidwall/gjson Vulnerable to REDoS attack
github.com/tidwall/gjson Vulnerable to REDoS attack
GJSON is a Go package that provides a fast and simple way to get values from a json document. GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
Microsoft
CVE-2021-42248: NIST NVD Details: https://nvd
vendor_msrc·2024-09-10·CVSS 7.5
CVE-2021-42248 [HIGH] CVE-2021-42248: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2021-42248
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Exploit Status: DOS:N/A
Remediation: keda
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-25
Published