Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-3433

Quick assessment

Affected
n/a aeson
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

aeson是Haskell开源的一个用于处理 JSON 数据的快速 Haskell 库。 aeson 存在安全漏洞,该漏洞源于其允许使用不受信任的JSON输入导致远程用户可以通过发送特别制作的JSON数据在底层无序容器库中产生散列冲突,从而导致拒绝服务。

AI Predicted 5.3 Difficulty: Moderate EPSS 0.74% · P52

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-3433

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
可逆的单向哈希
Source: CVE Program / CVE List V5
Vulnerability Title
aeson 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
aeson是Haskell开源的一个用于处理 JSON 数据的快速 Haskell 库。 aeson 存在安全漏洞,该漏洞源于其允许使用不受信任的JSON输入导致远程用户可以通过发送特别制作的JSON数据在底层无序容器库中产生散列冲突,从而导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- aeson Fixed in 2.0.1.0 -

II. Public POCs for CVE-2022-3433

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-3433

登录查看更多情报信息。

Security Blog Posts for CVE-2022-3433 (1)

Same Patch Batch · n/a · 2022-10-10 · 4 CVEs total

CVE-2022-26121 3.7 LOW Fortinet FortiManager和FortiAnalyzer 安全漏洞
CVE-2022-42725 Warpinator 后置链接漏洞
CVE-2022-42724 MISP 信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2022-3433

No comments yet


Leave a comment