CPANSA-Cpanel-JSON-XS-2023-01: Cpanel-JSON-XS vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2023-02-21T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2023-02-21T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 9.1 | Severity | |
Original language | Language | en | |
Also referred to |
Vulnerability Description
Wrong error messages/sometimes crashes or endless loops with invalid JSON in relaxed mode
Vulnerabilities
CVE-2022-48623
Vulnerability DescriptionThe Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
Weakness | CWE-125 : Out-of-bounds Read |
---|
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
Cpanel-JSON-XS less than 4.033 |
|
Fixed
- Cpanel-JSON-XS greater than or equal 4.033
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Cpanel-JSON-XS-2023-01 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2023/cpansa-cpanel-json-xs-2023-01.json - https://metacpan.org/changes/distribution/Cpanel-JSON-XS external
https://metacpan.org/changes/distribution/Cpanel-JSON-XS - https://github.com/rurban/Cpanel-JSON-XS/issues/208 external
https://github.com/rurban/Cpanel-JSON-XS/issues/208 - https://metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.33/changes external
https://metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.33/changes - https://nvd.nist.gov/vuln/detail/CVE-2022-48623 external
https://nvd.nist.gov/vuln/detail/CVE-2022-48623 - https://github.com/rurban/Cpanel-JSON-XS/commit/41f32396eee9395a40f9ed80145c37622560de9b external
https://github.com/rurban/Cpanel-JSON-XS/commit/41f32396eee9395a40f9ed80145c37622560de9b - https://github.com/advisories/GHSA-44qr-8pf6-6q33 external
https://github.com/advisories/GHSA-44qr-8pf6-6q33 - CVE-2022-48623 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2022-48623
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Tue Feb 21 00:00:00 2023 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/