Fedora Account System
Red Hat Associate
Red Hat Customer
In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect. To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale. https://github.com/eclipse-ee4j/parsson/pull/100 https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/13
This issue has been addressed in the following products: Cryostat 2 on RHEL 8 Via RHSA-2024:0530 https://access.redhat.com/errata/RHSA-2024:0530
This issue has been addressed in the following products: Red Hat build of Quarkus 3.2.10 Via RHSA-2024:0722 https://access.redhat.com/errata/RHSA-2024:0722
This issue has been addressed in the following products: RHBOAC camel-quarkus 3 (camel-4.0/quarkus-3.2) Via RHSA-2024:0789 https://access.redhat.com/errata/RHSA-2024:0789
This issue has been addressed in the following products: RHINT Camel-Springboot 4.0.3 Via RHSA-2024:0793 https://access.redhat.com/errata/RHSA-2024:0793
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Via RHSA-2024:1193 https://access.redhat.com/errata/RHSA-2024:1193
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2024:1192 https://access.redhat.com/errata/RHSA-2024:1192
This issue has been addressed in the following products: EAP 8.0.1 Via RHSA-2024:1194 https://access.redhat.com/errata/RHSA-2024:1194