CVE Vulnerabilities

CVE-2024-57699

Uncontrolled Recursion

Published: Feb 05, 2025 | Modified: Feb 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

Name Vendor Start Version End Version
Red Hat build of Apache Camel 4.8.5 for Spring Boot RedHat json-smart *
Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 RedHat quarkus-camel-bom *

Potential Mitigations

References