CVE-2024-47855 is a medium-severity vulnerability affecting JSON-lib versions prior to 3.1.0, specifically in the util/JSONTokener.java component, where it improperly handles unbalanced comment strings. This flaw allows for a denial-of-service (DoS) attack with low attack complexity and no user interaction required, as indicated by its CVSS score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Currently, there is no evidence of active exploitation, no publicly available exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.