CVE-2023-34610: High severity Json-io Project Json-io vulnerability
An issue was discovered json-io through 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Other sources
An issue was discovered json-io thru 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.cedarsoftware:json-ioto a version that resolves this vulnerability.Fixed in 4.14.1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34610?
CVE-2023-34610 is categorized as a denial of service vulnerability.
How do I fix CVE-2023-34610?
To remediate CVE-2023-34610, upgrade json-io to version 4.14.1 or later.
Which versions are affected by CVE-2023-34610?
CVE-2023-34610 affects json-io versions up to and including 4.14.0.
What impact does CVE-2023-34610 have on applications?
CVE-2023-34610 can lead to denial of service or other unspecified impacts due to cyclic dependencies.
Which software products are impacted by CVE-2023-34610?
CVE-2023-34610 affects json-io as well as various IBM products including Data Virtualization and Watson Query on Cloud Pak for Data.