Closed nidhi0512 closed 2 years ago
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Description
The package
JSON-java
before 20180130 is vulnerable to Denial of service. The methodJSONArray()
in classJSONArray()
of fileJSONArray.java
, doesn't check for unclosed array while parsing, causing the application to crash, due to an StackOverflowException. This affects the Availability of the application.HIGH Vulnerable Package issue exists @ org.json:json in branch master
Vulnerability ID: Cx08fcacc9-cb99
Package Name: org.json:json
Severity: HIGH
CVSS Score: 7.5
Publish Date: 2017-10-30T11:27:00
Current Package Version: 20131018
Remediation Upgrade Recommendation: 20200518
Link To SCA