python-cjson@1.0.3 vulnerabilities

Fast JSON encoder/decoder for Python

  • latest version

    1.2.2

  • latest non vulnerable version

  • first published

    18 years ago

  • latest version published

    4 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the python-cjson package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    Affected versions of python-cjson are vulnerable to Cross-Site Scripting (XSS) attacks.

    Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.

    How to fix Cross-site Scripting (XSS)?

    There is no fix version forpython-cjson.

    [,1.0.5]
    • M
    Denial of Service (DoS)

    python-cjson is a Fast JSON encoder/decoder for Python.

    Affected versions of this package are vulnerable to Denial of Service (DoS) attacks. Buffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is enabled, allows context-dependent attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors involving crafted Unicode input to the cjson.encode function.

    [1.0.0,1.0.5.1)