The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aeson | Haskell | * | 2.0.1.0 (excluding) |
Haskell-aeson | Ubuntu | bionic | * |
Haskell-aeson | Ubuntu | trusty | * |
Haskell-aeson | Ubuntu | upstream | * |
Haskell-aeson | Ubuntu | xenial | * |