CVE-2023-50246

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
13/12/2023
Last modified:
25/04/2025

Description

jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jqlang:jq:1.7:-:*:*:*:*:*:*
cpe:2.3:a:jqlang:jq:1.7:rc1:*:*:*:*:*:*
cpe:2.3:a:jqlang:jq:1.7:rc2:*:*:*:*:*:*