Input validation error in ultrajson - CVE-2022-31116
Published: July 5, 2022
Vulnerability identifier: #VU64940
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31116
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when decoding untrusted input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
ultrajson
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
Ubuntu
Cloud Pak for Security (CP4S)
srsly
QRadar Assistant
SUSE Linux Enterprise Module for Packagehub Subpackages
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-ujson-debuginfo
python2-ujson-debuginfo
python2-ujson
python3-ujson-debuginfo
python3-ujson
python-ujson-debugsource
python-ujson (Red Hat package)
dev-python/ujson
python-ujson
Spectrum Discover
Red Hat OpenStack
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
Ubuntu
Cloud Pak for Security (CP4S)
srsly
QRadar Assistant
SUSE Linux Enterprise Module for Packagehub Subpackages
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-ujson-debuginfo
python2-ujson-debuginfo
python2-ujson
python3-ujson-debuginfo
python3-ujson
python-ujson-debugsource
python-ujson (Red Hat package)
dev-python/ujson
python-ujson
Spectrum Discover
Red Hat OpenStack
How to mitigate CVE-2022-31116
Install updates from vendor's website.
ultrajson - update to 5.4.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0
srsly - update to 2.4.4
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson - update to 1.35-150100.3.5.1
python3-ujson-debuginfo - update to 1.35-150100.3.5.1
python3-ujson - update to 1.35-150100.3.5.1
python-ujson-debugsource - update to 1.35-150100.3.5.1
python-ujson (Red Hat package) - update to 2.0.3-3.el8ost
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
QRadar Assistant - update to 3.7.0
dev-python/ujson - update to 5.4.0
python-ujson - addressed in versions 5.4.0-1.el9, 5.4.0-1.fc35, 5.4.0-1.fc36
Red Hat OpenStack - addressed in versions 16.1.9, 16.2.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
srsly - update to 2.4.4
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson - update to 1.35-150100.3.5.1
python3-ujson-debuginfo - update to 1.35-150100.3.5.1
python3-ujson - update to 1.35-150100.3.5.1
python-ujson-debugsource - update to 1.35-150100.3.5.1
python-ujson (Red Hat package) - update to 2.0.3-3.el8ost
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
QRadar Assistant - update to 3.7.0
dev-python/ujson - update to 5.4.0
python-ujson - addressed in versions 5.4.0-1.el9, 5.4.0-1.fc35, 5.4.0-1.fc36
Red Hat OpenStack - addressed in versions 16.1.9, 16.2.4
External References
Related Security Bulletins
- Multiple vulnerabilities in ultrajson
- Denial of service in srsly
- SUSE update for python-ujson
- Red Hat OpenStack Platform 16.2 update for python-ujson
- Red Hat OpenStack Platform 16.1 update for python-ujson
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Discover
- Ubuntu update for ujson
- Ubuntu update for ujson
- Ubuntu update for ujson
- Gentoo update for UltraJSON
- Multiple vulnerabilities in IBM QRadar Assistant
- Fedora 36 update for python-ujson
- Fedora EPEL 9 update for python-ujson
- Fedora 35 update for python-ujson