漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
Vulnerability Description
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
使用不正确的解析名称或索引
Vulnerability Title
Dave Gamble cJSON 输入验证错误漏洞
Vulnerability Description
Dave Gamble cJSON是Dave Gamble个人开发者开源的一款轻量级的开源JSON解析器 Dave Gamble cJSON 1.5.0版本至1.7.19版本存在输入验证错误漏洞,该漏洞源于cJSON_Utils.c文件中的decode_pointer_inplace()函数错误解析名称或引用,未正确处理JSON Pointer转义序列(~0或~1),导致JSON Patch操作定位错误对象键,未经身份验证的攻击者可通过提交恶意RFC 6902 JSON Patch输入,造成数据损坏或删除
CVSS Information
N/A
Vulnerability Type
N/A