CVE Vulnerabilities

CVE-2022-3433

Inadequate Encryption Strength

Published: Oct 10, 2022 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Aeson Haskell * 2.0.1.0 (excluding)
Haskell-aeson Ubuntu bionic *
Haskell-aeson Ubuntu trusty *
Haskell-aeson Ubuntu upstream *
Haskell-aeson Ubuntu xenial *

Potential Mitigations

References