CVE-2023-4043
Parsson DoS when parsing numbers from untrusted sources
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.
To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.
En Eclipse Parsson antes de las versiones 1.1.4 y 1.0.5, el Parsing JSON de fuentes no confiables puede llevar a actores maliciosos a explotar el hecho de que el soporte integrado para analizar números a gran escala en Java tiene varios casos extremos en los que el texto de entrada de un número puede llevar a un tiempo de procesamiento mucho mayor de lo que cabría esperar. Para mitigar el riesgo, parsson estableció un límite de tamaño para los números y su escala.
A flaw was found in Eclipse Parsson library when processing untrusted source content. This issue may cause a Denial of Service (DoS) due to built-in support for parsing numbers with a large scale, and some cases where processing a large number may take much more time than expected.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-08-01 CVE Reserved
- 2023-11-03 CVE Published
- 2024-09-05 CVE Updated
- 2024-09-05 First Exploit
- 2024-11-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-834: Excessive Iteration
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/13 | 2024-09-05 |
URL | Date | SRC |
---|---|---|
https://github.com/eclipse-ee4j/parsson/pull/100 | 2023-11-13 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-4043 | 2024-03-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2254594 | 2024-03-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Parsson Search vendor "Eclipse" for product "Parsson" | < 1.0.5 Search vendor "Eclipse" for product "Parsson" and version " < 1.0.5" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Parsson Search vendor "Eclipse" for product "Parsson" | >= 1.1.0 < 1.1.4 Search vendor "Eclipse" for product "Parsson" and version " >= 1.1.0 < 1.1.4" | - |
Affected
|