CVE-2021-31684: High severity ibm planning analytics vulnerability
A flaw was found in the json-smart package in the JSONParserByteArray. This flaw allows an attacker to cause a denial of service.
Other sources
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions prior to 1.3.3 and 2.4.5 which causes a denial of service (DOS) via a crafted web request.
— GitHub
netplex JSON Smart is vulnerable to a denial of service, caused by a flaw in the indexOf function of JSONParserByteArray. By sending a specially-crafted web request, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw in the JSONParserByteArray?
The vulnerability ID of this flaw in the JSONParserByteArray is CVE-2021-31684.
What is the severity of CVE-2021-31684?
The severity of CVE-2021-31684 is high with a severity value of 7.5.
Which versions of JSON Smart are affected by CVE-2021-31684?
CVE-2021-31684 affects JSON Smart versions 1.3 and 2.4.
What is the impact of CVE-2021-31684?
CVE-2021-31684 causes a denial of service (DOS) via a crafted web request.
Are there any references available for CVE-2021-31684?
Yes, there are references available for CVE-2021-31684. You can find them at the following links: [GitHub Issue 10](https://github.com/netplex/json-smart-v1/issues/10), [GitHub Pull Request 11](https://github.com/netplex/json-smart-v1/pull/11), [GitHub Issue 67](https://github.com/netplex/json-smart-v2/issues/67).