Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:3752", "cpe": "cpe:/a:redhat:amq_broker:7.10", "package": "hawtio-war", "product_name": "Red Hat AMQ Broker 7", "release_date": "2024-06-10T00:00:00Z"}, {"advisory": "RHSA-2024:3762", "cpe": "cpe:/a:redhat:amq_broker:7.11", "package": "hawtio-war", "product_name": "Red Hat AMQ Broker 7", "release_date": "2024-06-10T00:00:00Z"}, {"advisory": "RHSA-2024:4271", "cpe": "cpe:/a:redhat:amq_broker:7.12", "package": "hawtio-war", "product_name": "Red Hat AMQ Broker 7", "release_date": "2024-07-02T00:00:00Z"}, {"advisory": "RHSA-2023:7678", "cpe": "cpe:/a:redhat:amq_streams:2", "product_name": "Red Hat AMQ Streams 2.6.0", "release_date": "2023-12-06T00:00:00Z"}, {"advisory": "RHSA-2023:7617", "cpe": "cpe:/a:redhat:camel_quarkus:3.2.0", "product_name": "Red Hat build of Apache Camel 4 for Quarkus 3", "release_date": "2023-11-30T00:00:00Z"}, {"advisory": "RHSA-2024:3354", "cpe": "cpe:/a:redhat:jboss_fuse:7", "impact": "low", "package": "JSON-java", "product_name": "Red Hat Fuse 7.13.0", "release_date": "2024-05-23T00:00:00Z"}, {"advisory": "RHSA-2024:0148", "cpe": "cpe:/a:redhat:camel_k:1.10.5", "package": "JSON-java", "product_name": "RHINT Camel-K 1.10.5", "release_date": "2024-01-10T00:00:00Z"}, {"advisory": "RHSA-2023:7845", "cpe": "cpe:/a:redhat:camel_spring_boot:3.20.4", "package": "JSON-java", "product_name": "RHINT Camel-Springboot 3.20.4", "release_date": "2023-12-14T00:00:00Z"}, {"advisory": "RHSA-2023:7842", "cpe": "cpe:/a:redhat:camel_spring_boot:4.0.2", "product_name": "RHINT Camel-Springboot 4.0.2", "release_date": "2023-12-14T00:00:00Z"}, {"advisory": "RHSA-2024:1353", "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7.13", "package": "JSON-java", "product_name": "RHPAM 7.13.5 async", "release_date": "2024-03-18T00:00:00Z"}], "bugzilla": {"description": "JSON-java: parser confusion leads to OOM", "id": "2246417", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246417"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "status": "verified"}, "cwe": "CWE-770", "details": ["Denial of Service in JSON-Java versions up to and including 20230618. \u00a0A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.", "A flaw was found in the org.json package. A bug in the parser exists, and an input string may lead to undefined usage of memory, leading to an out-of-memory error, causing a denial of service (DoS)."], "mitigation": {"lang": "en:us", "value": "No current mitigation is available for this flaw."}, "name": "CVE-2023-5072", "package_state": [{"cpe": "cpe:/a:redhat:serverless:1", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "OpenShift Serverless"}, {"cpe": "cpe:/a:redhat:ansible_automation_platform:2", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat Ansible Automation Platform 2"}, {"cpe": "cpe:/a:redhat:service_registry:2", "fix_state": "Affected", "package_name": "JSON-java", "product_name": "Red Hat build of Apicurio Registry 2"}, {"cpe": "cpe:/a:redhat:debezium:2", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat build of Debezium 2"}, {"cpe": "cpe:/a:redhat:jboss_data_grid:8", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat Data Grid 8"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:7", "fix_state": "Affected", "package_name": "JSON-java", "product_name": "Red Hat Decision Manager 7"}, {"cpe": "cpe:/a:redhat:camel_quarkus:2", "fix_state": "Affected", "package_name": "JSON-java", "product_name": "Red Hat Integration Camel Quarkus 2"}, {"cpe": "cpe:/a:redhat:jboss_data_grid:7", "fix_state": "Will not fix", "package_name": "JSON-java", "product_name": "Red Hat JBoss Data Grid 7"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Out of support scope", "package_name": "JSON-java", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat JBoss Enterprise Application Platform 7"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat JBoss Enterprise Application Platform 8"}, {"cpe": "cpe:/a:redhat:jbosseapxp", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"}, {"cpe": "cpe:/a:redhat:jboss_fuse:6", "fix_state": "Out of support scope", "package_name": "JSON-java", "product_name": "Red Hat JBoss Fuse 6"}, {"cpe": "cpe:/a:redhat:jboss_fuse_service_works:6", "fix_state": "Out of support scope", "package_name": "JSON-java", "product_name": "Red Hat JBoss Fuse Service Works 6"}, {"cpe": "cpe:/a:redhat:red_hat_single_sign_on:7", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "Red Hat Single Sign-On 7"}, {"cpe": "cpe:/a:redhat:amq_streams:1", "fix_state": "Not affected", "package_name": "JSON-java", "product_name": "streams for Apache Kafka"}], "public_date": "2023-10-12T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2023-5072\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-5072\nhttps://github.com/stleary/JSON-java/issues/758\nhttps://github.com/stleary/JSON-java/issues/771"], "statement": "This vulnerability may cause denial of service with a small string input, causing the server to be unresponsive easily, hence the Important impact.", "threat_severity": "Important"}