CVE-2024-21907

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/01/2024
Last modified:
06/09/2024

Description

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:newtonsoft:json.net:*:*:*:*:*:*:*:* 13.0.1 (excluding)