CVE-2021-42248: High severity gjson vulnerability
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-ppj4-34rq-v8j9. This link is maintained to preserve external references.
Original Description GJSON <= 1.9.2 allows attackers to cause a redos via crafted JSON input.
Other sources
GJSON is vulnerable to a denial of service, caused by a flaw in the gjson.Get function. By sending a specially-crafted JSON input, a remote attacker could exploit this vulnerability to cause a denial of service.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42836. Reason: This candidate is a duplicate of CVE-2021-42836. Notes: All CVE users should reference CVE-2021-42836 instead of this candidate.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-42248.
What is the severity of CVE-2021-42248?
The severity of CVE-2021-42248 is high (7.5).
Which software versions are affected by CVE-2021-42248?
GJSON versions up to and including 1.9.2, IBM Cloud Pak for Security versions 1.10.0.0 to 1.10.11.0, and IBM QRadar Suite Software versions 1.10.12.0 to 1.10.16.0 are affected.
What is the impact of CVE-2021-42248?
CVE-2021-42248 can be exploited by a remote attacker to cause a denial of service (DoS).
Is there a fix available for CVE-2021-42248?
It is recommended to update to a patched version of the affected software to fix CVE-2021-42248.