CVE-2021-27568: Infoleak
A flaw was found in json-smart. When an exception is thrown from a function, but is not caught, the program using the library may crash or expose sensitive information. The highest threat from this vulnerability is to data confidentiality and system availability. In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of json-smart package. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/releasenotes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated
Other sources
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
Netplex json-smart-v1 and json-smart-v2 are vulnerable to a denial of service, caused by an uncaught exception flaw in NumberFormatException. By sending a specially-crafted input, a remote attacker could exploit this vulnerability to cause the library to crash or obtain sensitive information.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-27568?
CVE-2021-27568 is a vulnerability found in json-smart library that can cause program crashes or expose sensitive information when an exception is thrown from a function and not caught.
What is the severity of CVE-2021-27568?
CVE-2021-27568 has a severity rating of medium with a CVSS score of 5.9.
Which software versions are affected by CVE-2021-27568?
CVE-2021-27568 affects json-smart-v1 up to 1.3.2 and json-smart-v2 up to 2.4.1.
How can CVE-2021-27568 impact my system?
CVE-2021-27568 can potentially compromise data confidentiality and system availability.
Where can I find more information about CVE-2021-27568?
You can find more information about CVE-2021-27568 on the GitHub pages of json-smart-v1 and json-smart-v2, as well as the Red Hat Security Advisory RHSA-2021:3225.