CVE-2023-7272

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
17/07/2024
Last modified:
06/02/2025

Description

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:parsson:*:*:*:*:*:*:*:* 1.0.4 (excluding)
cpe:2.3:a:eclipse:parsson:*:*:*:*:*:*:*:* 1.1.0 (including) 1.1.3 (excluding)