Skip to main content

Uncaught Exception in org.json:json

Cx08fcacc9-cb99

  • org.json:json
Severity High
Score 7.5/10

Summary

The package `JSON-java` before 20180130 is vulnerable to Denial of service. The method `JSONArray()` in class `JSONArray()` of file `JSONArray.java`, doesn't check for unclosed array while parsing, causing the application to crash, due to an StackOverflowException. This affects the Availability of the application.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-248 - Uncaught Exception

An exception is thrown from a function, but it is not caught.

Advisory Timeline

  • Published