Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-19436

CVE-2021-31684 json-smart version

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Major
    • None
    • fuse-7.11-GA
    • Karaf
    • None
    • False
    • None
    • False
    • % %
    • Todo

    Description

      Checking the CVE-2021-31684 bugzilla[1], it seems that versions prior to 2.4.4 which causes a denial of service (DOS) via a crafted web request. Fuse current version, 7.11, ships the 2.4.1.

      It could be updated?

      [1]https://bugzilla.redhat.com/show_bug.cgi?id=2102695

      Attachments

        Activity

          Public project attachment banner

            context keys: [headless, issue, helper, isAsynchronousRequest, project, action, user]
            current Project key: ENTESB

            People

              Unassigned Unassigned
              emunoz@redhat.com Elkin Munoz
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: