CVE-2024-21907
HIGHNewtonsoft Json.net < 13.0.1 - Improper Exception Handling
Title source: ruleDescription
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
Scores
CVSS v3
7.5
EPSS
0.0233
EPSS Percentile
84.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-755
Status
published
Products (2)
newtonsoft/json.net
< 13.0.1
nuget/Newtonsoft.Json
0 - 13.0.1NuGet
Published
Jan 03, 2024
Tracked Since
Feb 18, 2026