Improper Validation of Array Index in GJSON
High severity
GitHub Reviewed
Published
Feb 6, 2023
to the GitHub Advisory Database
•
Updated Feb 6, 2023
Description
Published to the GitHub Advisory Database
Feb 6, 2023
Reviewed
Feb 6, 2023
Last updated
Feb 6, 2023
GJSON < 1.6.6 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.
References