Cloudflare Vulnerabilities and Affected Products
Vulnerabilities associated with lua-resty-json.
Products
Clear product- WARP14 vulnerabilities
- octorpki9 vulnerabilities
- quiche9 vulnerabilities
- WARP Client4 vulnerabilities
- Wrangler4 vulnerabilities
- https://github.com/cloudflare/pingora3 vulnerabilities
- CIRCL2 vulnerabilities
- cloudflared2 vulnerabilities
- cfnts1 vulnerability
- Cloudflare WARP for Windows1 vulnerability
- Cloudflare-WordPress1 vulnerability
- goflow1 vulnerability
- gokey1 vulnerability
- https://github.com/cloudflare/pages-action1 vulnerability
- lol-html1 vulnerability
- lua-resty-json1 vulnerability
- miniflare1 vulnerability
- odoh-rs1 vulnerability
- tokio-boring1 vulnerability
- Universal SSL1 vulnerability
- workerd1 vulnerability
- workers-sdk1 vulnerability
- zlib1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Out of Bounds Access Leading to Undefined BehaviorA debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug function was only used in tests and demos, it was not exploitable in a normal environment. CWE-125Jun 14, 2023 | CVSS3.7v3.1 | EPSS0.71% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |