Parsson DoS when parsing numbers from untrusted sources
CVE-2023-4043

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 November 2023

What is CVE-2023-4043?

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.

To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

Affected Version(s)

Parsson 0 < 1.0.5

Parsson 1.1.0 < 1.1.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuan Tian
.