CVE-2024-31755 describes a segmentation violation in cJSON v1.7.17, specifically triggered via the cJSON_SetValuestring function, affecting the cjson_project cjson library. This vulnerability carries a high CVSS score of 7.6, indicating a network-exploitable flaw with low attack complexity, requiring low privileges, and potentially leading to significant impact on availability, along with some impact on confidentiality and integrity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.17CPE matchmatch criteria | cpe:2.3:a:cjson_project:cjson:1.7.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-31755
Jul 9, 2024cjson: segmentation violation trigger through the second parameter of function cJSON_SetValuestring at cJSON.c
Apr 26, 2024cJSON v1.7.17 was discovered to contain a segmentation violation which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.
Apr 9, 2024