CVE-2024-21907
high · 7.5Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
7.5
CVSS
32.9%
EPSS (exploit prob.)
98th
EPSS percentile
2024-01-03
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-755
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| newtonsoft | json.net | < 13.0.1 |
Check a specific version with /api/v1/cve/match.
References
- https://alephsecurity.com/2018/10/22/StackOverflowException/
- https://alephsecurity.com/vulns/aleph-2018004
- https://github.com/JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66
- https://github.com/JamesNK/Newtonsoft.Json/issues/2457
- https://github.com/JamesNK/Newtonsoft.Json/pull/2462
- https://github.com/advisories/GHSA-5crp-9r3c-p9vr
- https://security.snyk.io/vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678
- https://vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vr
- https://alephsecurity.com/2018/10/22/StackOverflowException/
- https://alephsecurity.com/vulns/aleph-2018004
- https://github.com/JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66
- https://github.com/JamesNK/Newtonsoft.Json/issues/2457
- https://github.com/JamesNK/Newtonsoft.Json/pull/2462
- https://github.com/advisories/GHSA-5crp-9r3c-p9vr
- https://security.snyk.io/vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678
- https://vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vr
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-21907