Input validation error in ultrajson - CVE-2022-31116

 

Input validation error in ultrajson - CVE-2022-31116

Published: July 5, 2022


Vulnerability identifier: #VU64940
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31116
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error when decoding untrusted input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

ultrajson
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
Ubuntu
Cloud Pak for Security (CP4S)
srsly
QRadar Assistant
SUSE Linux Enterprise Module for Packagehub Subpackages
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-ujson-debuginfo
python2-ujson-debuginfo
python2-ujson
python3-ujson-debuginfo
python3-ujson
python-ujson-debugsource
python-ujson (Red Hat package)
dev-python/ujson
python-ujson
Spectrum Discover
Red Hat OpenStack

How to mitigate CVE-2022-31116

Install updates from vendor's website.

ultrajson - update to 5.4.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0
srsly - update to 2.4.4
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson - update to 1.35-150100.3.5.1
python3-ujson-debuginfo - update to 1.35-150100.3.5.1
python3-ujson - update to 1.35-150100.3.5.1
python-ujson-debugsource - update to 1.35-150100.3.5.1
python-ujson (Red Hat package) - update to 2.0.3-3.el8ost
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
QRadar Assistant - update to 3.7.0
dev-python/ujson - update to 5.4.0
python-ujson - addressed in versions 5.4.0-1.el9, 5.4.0-1.fc35, 5.4.0-1.fc36
Red Hat OpenStack - addressed in versions 16.1.9, 16.2.4

External References

Related Security Bulletins