CVE-2023-33008
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and maybe use numbers too large which may result in a slow conversion (Denial of service risk). Apache Johnzon 1.2.21 mitigates this by setting a scale limit of 1000 (by default) to the BigDecimal. This issue affects Apache Johnzon: through 1.2.20.
Published:Jul 6, 2023
Last Modified:Nov 21, 2024
EPS:Jul 7, 2023
EPSS Score:0.00091
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Johnzon
Apache
Johnzon
Vendor
Redhat
Product
Amq Broker
Redhat
Amq Broker
Vendor
Redhat
Product
Camel Spring Boot
Redhat
Camel Spring Boot
Vendor
Redhat
Product
Openshift Application Runtimes
Redhat
Openshift Application Runtimes
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
