GO-2021-0265
Dashboard / Vulnerabilities / GO-2021-0265
GO-2021-0265
Published: 15 Aug 2022Last Modified: 20 May 2024
Summary: Denial of service via maliciously crafted path in github.com/tidwall/gjson
Details: A maliciously crafted path can cause Get and other query functions to consume excessive amounts of CPU and time.
References: https://github.com/tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96, https://github.com/tidwall/gjson/issues/237, https://github.com/tidwall/gjson/issues/236, https://github.com/tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944
Affected packages
Package
Name: github.com/tidwall/gjson
Purl: pkg:golang/github.com/tidwall/gjson
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.9.3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
