High severity7.5NVD Advisory· Published Jun 1, 2021· Updated Jun 17, 2026
CVE-2021-31684
CVE-2021-31684
Description
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.minidev:json-smartMaven | >= 1.3.0, < 1.3.3 | 1.3.3 |
net.minidev:json-smartMaven | >= 2.4.0, < 2.4.4 | 2.4.4 |
Affected products
26- cpe:2.3:a:json-smart_project:json-smart-v1:*:*:*:*:*:*:*:*Range: >=1.3,<1.3.3
- cpe:2.3:a:json-smart_project:json-smart-v2:*:*:*:*:*:*:*:*Range: >=2.4,<2.4.4
cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_framework:4.4.0.3.0:*:*:*:*:*:*:*
- JSON Smart/JSON Smartdescription
- osv-coords20 versionspkg:apk/chainguard/celeborn-0.5pkg:apk/chainguard/celeborn-0.6pkg:apk/chainguard/druidpkg:apk/chainguard/hadoop-client-modulespkg:apk/chainguard/spark-3.5.0-compatpkg:apk/chainguard/spark-3.5.0-compat-minimalpkg:apk/chainguard/thingsboardpkg:apk/chainguard/thingsboard-tb-js-executorpkg:apk/chainguard/thingsboard-tb-mqtt-transportpkg:apk/chainguard/thingsboard-tb-nodepkg:apk/chainguard/thingsboard-tb-web-uipkg:apk/wolfi/celeborn-0.5pkg:apk/wolfi/celeborn-0.6pkg:apk/wolfi/druidpkg:apk/wolfi/thingsboardpkg:apk/wolfi/thingsboard-tb-js-executorpkg:apk/wolfi/thingsboard-tb-mqtt-transportpkg:apk/wolfi/thingsboard-tb-nodepkg:apk/wolfi/thingsboard-tb-web-uipkg:maven/net.minidev/json-smart
< 0.5.4-r26+ 19 more
- (no CPE)range: < 0.5.4-r26
- (no CPE)range: < 0.6.3-r7
- (no CPE)range: < 37.0.0-r14
- (no CPE)range: < 3.3.6-r7
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 0.5.4-r26
- (no CPE)range: < 0.6.3-r7
- (no CPE)range: < 37.0.0-r14
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: < 3.7-r4
- (no CPE)range: >= 1.3.0, < 1.3.3
Patches
Vulnerability mechanics
References
11- github.com/netplex/json-smart-v1/pull/11nvdPatchThird Party AdvisoryWEB
- github.com/netplex/json-smart-v2/pull/68nvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/netplex/json-smart-v2/issues/67nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-fg2v-w576-w4v3ghsaADVISORY
- github.com/netplex/json-smart-v1/issues/10nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-31684ghsaADVISORY
- lists.debian.org/debian-lts-announce/2023/03/msg00030.htmlnvdWEB
- security.netapp.com/advisory/ntap-20240621-0006ghsaWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdWEB
- security.netapp.com/advisory/ntap-20240621-0006/nvd
News mentions
0No linked articles in our index yet.