cbcvebase.
CVE-2023-33460
published 2023-06-06

CVE-2023-33460: There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

PriorityP424medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.13%
62.7th percentile
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianepics-base< r-cran-jsonlite 1.8.8+dfsg-1 (forky)r-cran-jsonlite 1.8.8+dfsg-1 (forky)
debianr-cran-jsonlite< r-cran-jsonlite 1.8.8+dfsg-1 (forky)r-cran-jsonlite 1.8.8+dfsg-1 (forky)
debianruby-yajl< r-cran-jsonlite 1.8.8+dfsg-1 (forky)r-cran-jsonlite 1.8.8+dfsg-1 (forky)
debianyajl< r-cran-jsonlite 1.8.8+dfsg-1 (forky)r-cran-jsonlite 1.8.8+dfsg-1 (forky)
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_yajl_2.1.0-19_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_yajl_2.1.0-19_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_yajl_2.1.0-18_on_cbl_mariner_1.0
yajl_projectyajl
yajl_projectyajl>= 0 < 2.1.0-3+deb11u22.1.0-3+deb11u2
yajl_projectyajl>= 0 < 2.1.0-3+deb12u22.1.0-3+deb12u2
yajl_projectyajl>= 0 < 2.1.0-52.1.0-5
yajl_projectyajl>= 0 < 2.1.0-52.1.0-5

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.