Executive brief
A vulnerability exists in the hjson-java library, which is used to parse Hjson (Human JSON) data formats. An attacker can send specially crafted, deeply nested data structures to an application using this library, causing the application to crash or become unresponsive. This results in a denial of service, potentially disrupting business operations and service availability.
Technical details
The hjson-java library (up to and including version 3.0.0) is susceptible to uncontrolled recursion (CWE-674) when parsing Hjson input. By providing a crafted object with deeply nested structures, a remote attacker can trigger stack exhaustion or uncontrolled resource consumption (CWE-400). This typically results in a StackOverflowError, causing the Java Virtual Machine (JVM) or the specific application thread to crash, leading to a denial of service (DoS). The vulnerability is reachable over the network without authentication if the application parses user-supplied Hjson data. As of the advisory date, no patched version is specified.
Affected products
- hjson hjson-java <= 3.0.0
Timeline
- 2023-06-14: advisory: GitHub Advisory published
- 2023-06-14: disclosed: NVD publication date