CVE-2022-21653
Description
Jawn is an open source JSON parser. Extenders of the org.typelevel.jawn.SimpleFacade
and org.typelevel.jawn.MutableFacade
who don't override objectContext()
are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. jawn-parser-1.3.1
fixes this issue and users are advised to upgrade. For users unable to upgrade override objectContext()
to use a collision-safe collection.
- CVSS Version 3.1
- CVSS Version 2.0
nvd
CVE ID: CVE-2022-21653
Base Score: 7.5
Base Severity: HIGH
Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 3.9
github
CVE ID: CVE-2022-21653
Base Score: 5.9
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.2
nvd
CVE ID: CVE-2022-21653
Base Score: 5.0
Base Severity: MEDIUM
Vector String:AV:N/AC:L/Au:N/C:N/I:N/A:P