发布于3月6日3月6日 Members Ubuntu: USN-6011-1 (CVE-2023-1370): Json-smart vulnerabilities Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:N/A:C) Published 03/22/2023 Created 05/05/2023 Added 04/17/2023 Modified 01/28/2025 Description [Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the code does not have any limit to the nesting of such arrays or objects. Since the parsing of nested arrays and objects is done recursively, nesting too many of them can cause a stack exhaustion (stack overflow) and crash the software. Solution(s) ubuntu-upgrade-libjson-smart-java References https://attackerkb.com/topics/cve-2023-1370 CVE - 2023-1370 USN-6011-1