CVE-2022-45688: High severity Hutool Hutool vulnerability
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Other sources
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 and org.json:json before version 20230227 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45688?
CVE-2022-45688 is a vulnerability in the XML.toJSONObject component of hutool-json v5.8.10 that allows attackers to cause a denial of service by exploiting a stack-based buffer overflow.
What is the severity of CVE-2022-45688?
CVE-2022-45688 has a severity rating of 7.5 (High).
Which software versions are affected by CVE-2022-45688?
Hutool v5.8.10 and Json-java Project v20230227 are affected by CVE-2022-45688.
How can an attacker exploit CVE-2022-45688?
An attacker can exploit CVE-2022-45688 by sending a specially crafted request to the vulnerable application, causing a stack-based buffer overflow and crashing the application.
Are there any references for CVE-2022-45688?
Yes, you can find references for CVE-2022-45688 at the following links: [Link 1](https://github.com/dromara/hutool/issues/2748), [Link 2](https://github.com/stleary/JSON-java/issues/708), [Link 3](https://exchange.xforce.ibmcloud.com/vulnerabilities/242881).