bungeecord-prometheus-exporter icon indicating copy to clipboard operation
bungeecord-prometheus-exporter copied to clipboard

CVE-2023-51074 (Medium) detected in json-path-2.7.0.jar

Open mend-bolt-for-github[bot] opened this issue 6 months ago • 0 comments

CVE-2023-51074 - Medium Severity Vulnerability

Vulnerable Library - json-path-2.7.0.jar

Java port of Stefan Goessner JsonPath.

Library home page: https://github.com/

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

  • :x: json-path-2.7.0.jar (Vulnerable Library)

Found in base branch: main

Vulnerability Details

json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.

Publish Date: 2023-12-27

URL: CVE-2023-51074

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.cve.org/CVERecord?id=CVE-2023-51074

Release Date: 2023-12-27

Fix Resolution: 2.9.0


Step up your Open Source Security Game with Mend here