CVE Vulnerabilities

CVE-2022-31116

Always-Incorrect Control Flow Implementation

Published: Jul 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly. Besides corrupting strings, this allowed for potential key confusion and value overwriting in dictionaries. All users parsing JSON from untrusted sources are vulnerable. From version 5.4.0, UltraJSON decodes lone surrogates in the same way as the standard librarys json module does, preserving them in the parsed output. Users are advised to upgrade. There are no known workarounds for this issue.

Weakness

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

Affected Software

Name Vendor Start Version End Version
Ultrajson Ultrajson_project * 5.4.0 (excluding)
Red Hat OpenStack Platform 16.1 RedHat python-ujson-0:2.0.3-3.el8ost *
Red Hat OpenStack Platform 16.2 RedHat python-ujson-0:2.0.3-3.el8ost *
Collada2gltf Ubuntu bionic *
Collada2gltf Ubuntu impish *
Collada2gltf Ubuntu kinetic *
Collada2gltf Ubuntu lunar *
Collada2gltf Ubuntu xenial *
Pandas Ubuntu bionic *
Pandas Ubuntu impish *
Pandas Ubuntu kinetic *
Pandas Ubuntu lunar *
Pandas Ubuntu mantic *
Pandas Ubuntu trusty *
Pandas Ubuntu trusty/esm *
Pandas Ubuntu upstream *
Pandas Ubuntu xenial *
Ujson Ubuntu bionic *
Ujson Ubuntu esm-apps/bionic *
Ujson Ubuntu esm-apps/focal *
Ujson Ubuntu esm-apps/jammy *
Ujson Ubuntu esm-apps/xenial *
Ujson Ubuntu focal *
Ujson Ubuntu impish *
Ujson Ubuntu jammy *
Ujson Ubuntu upstream *
Ujson Ubuntu xenial *

References