Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-23900

Description

OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations.

POC

Reference

No PoCs from references.

Github

- https://github.com/CodeIntelligenceTesting/jazzer

- https://github.com/TinkerBoard-Android/rockchip-android-external-jazzer-api

- https://github.com/msft-mirror-aosp/platform.external.jazzer-api