Ion Java StackOverflow vulnerability
CVE-2024-21634
What is CVE-2024-21634?
A potential denial-of-service vulnerability exists in the Amazon Ion library, specifically in versions prior to 1.10.5 of the ion-java implementation. This issue arises when applications attempt to deserialize Ion text encoded data or transform Ion text or binary data into the IonValue model. If an attacker crafts malicious Ion data, loading it into an affected application can trigger a StackOverflowError when specific IonValue methods are invoked. To mitigate this issue, it is crucial to avoid processing data from untrusted sources or data that may have been compromised. Users are strongly advised to upgrade to ion-java version 1.10.5 or later to incorporate the necessary patch.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ion-java < 1.10.5
News Articles
References
CVSS V3.1
Timeline
- đź“°
First article discovered by iTnews
Vulnerability published
Vulnerability Reserved
