Medium severity5.9NVD Advisory· Published Feb 23, 2021· Updated Jun 17, 2026
CVE-2021-27568
CVE-2021-27568
Description
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.minidev:json-smartMaven | < 1.3.2 | 1.3.2 |
net.minidev:json-smartMaven | >= 2.4.0, < 2.4.1 | 2.4.1 |
net.minidev:json-smart-miniMaven | < 1.3.2 | 1.3.2 |
net.minidev:json-smartMaven | >= 2.0.0, < 2.3.1 | 2.3.1 |
Affected products
16- cpe:2.3:a:json-smart_project:json-smart-v1:*:*:*:*:*:*:*:*Range: <1.3.2
- cpe:2.3:a:json-smart_project:json-smart-v2:*:*:*:*:*:*:*:*Range: <2.3.1
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oss_support_tools:*:*:*:*:*:*:*:*Range: <2.12.42
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_framework:4.4.0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
- netplex/json-smartdescription
- osv-coords3 versionspkg:apk/chainguard/hadoop-fips-3.3.6pkg:maven/net.minidev/json-smartpkg:maven/net.minidev/json-smart-mini
< 3.3.6-r21+ 2 more
- (no CPE)range: < 3.3.6-r21
- (no CPE)range: < 1.3.2
- (no CPE)range: < 1.3.2
Patches
Vulnerability mechanics
References
16- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/netplex/json-smart-v1/issues/7nvdExploitThird Party AdvisoryWEB
- github.com/netplex/json-smart-v2/issues/60nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-v528-7hrm-frqpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-27568ghsaADVISORY
- github.com/netplex/json-smart-v1/commit/768db58ee0e3e344fcdb574b7629765308a1d0afghsaWEB
- github.com/netplex/json-smart-v2/issues/62ghsaWEB
- github.com/netplex/json-smart-v2/pull/72ghsaWEB
- lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3Envd
News mentions
0No linked articles in our index yet.