CVE-2024-21907
newtonsoft json.net
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
- CVSS
- 7.5
- EPSS
- 32.9% 98.2% percentile
- CISA KEV
- Not listed
- Published
- 2024.01.04