Improper Input Validation Affecting org.apache.sling:org.apache.sling.commons.json package, versions [,2.0.24)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.54% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHESLING-5535052
  • published15 May 2023
  • disclosed15 May 2023
  • creditBIngDiAn

Introduced: 15 May 2023

CVE-2022-47937  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade org.apache.sling:org.apache.sling.commons.json to version 2.0.24 or higher.

Overview

org.apache.sling:org.apache.sling.commons.json is a Sling JSON library

Affected versions of this package are vulnerable to Improper Input Validation that allows an attacker to trigger unexpected errors by supplying specially crafted input. Exploiting this vulnerability might result in out-of-memory and stack-overflows.

NOTE: This issue was unfixed for a long time as the repository hasn't been maintained since 2017.

CVSS Scores

version 3.1