CVE-2023-5072 is a Denial of Service vulnerability affecting JSON-Java versions up to and including 20230618. A flaw in the parser allows a modestly sized input string to consume indefinite amounts of memory, leading to resource exhaustion. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, resulting in a complete loss of availability. There is currently no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20230618CPE matchmatch criteria | cpe:2.3:a:stleary:json-java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.