CVE-2022-45688

HIGH

Hutool < 20230227 - Out-of-Bounds Write

Title source: rule

Description

A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

Exploits (5)

nomisec WORKING POC 1 stars
by scabench · poc
https://github.com/scabench/jsonorg-fn1
nomisec WORKING POC
by scabench · poc
https://github.com/scabench/jsonorg-tp1
nomisec WRITEUP
by scabench · poc
https://github.com/scabench/jsonorg-fp3
nomisec WRITEUP
by scabench · poc
https://github.com/scabench/jsonorg-fp2
nomisec WRITEUP
by scabench · poc
https://github.com/scabench/jsonorg-fp1

Scores

CVSS v3 7.5
EPSS 0.0115
EPSS Percentile 78.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (4)
cn.hutool/hutool-json 0 - 5.8.25Maven
hutool/hutool 5.8.10
org.json/json 0 - 20230227Maven
stleary/json-java < 20230227
Published Dec 13, 2022
Tracked Since Feb 18, 2026