-
Notifications
You must be signed in to change notification settings - Fork 437
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security - CVE-2020-10675 #258
Comments
As far as I can tell, this was fixed with #192 ; and released in https://github.com/buger/jsonparser/releases/tag/v1.0.0 . |
That's very interesting, I wonder what are the details of this issue 🤔 1.1.1 had fix for https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35381, but that's one different. |
So here is what fixed the issue #188, @milosonator is right. I wonder how to remove this CVE from databases 🤔 |
Github, for example, mark it as fixed in 1.0.0 GHSA-rmh2-65xw-9m6q |
@buger Looks like the CPE on the vulnerability may be too inclusive and would flag for all versions. Blackduck (the tool in the screenshot) uses CPEs to determine what is the affected versions. |
jsonparserv1.1.1 has a critical vulnerability found
CVE-2020-10675
The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.
The text was updated successfully, but these errors were encountered: