Skip to content

JSON vulnerability in 0.10.2 datahub version

High
david-leifker published GHSA-7fpm-2gq5-7r2g Aug 14, 2023

Package

No package listed

Affected versions

<=v0.10.2

Patched versions

>=v0.10.3

Description

Summary

A stack overflow in the XML.toJSONObject component allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

Details

Third-party dependency.

Resolution

Upgraded to 20230227 in v0.10.3

Impact

Denial of Service (DoS)

Severity

High

CVE ID

CVE-2022-45688

Weaknesses

No CWEs