Medium severity5.9NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026
CVE-2023-4043
CVE-2023-4043
Description
In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.
To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.eclipse.parsson:projectMaven | >= 1.1.0, < 1.1.4 | 1.1.4 |
org.eclipse.parsson:projectMaven | < 1.0.5 | 1.0.5 |
Affected products
3- Eclipse Foundation/Parssonv5Range: 0
Patches
Vulnerability mechanics
References
4- github.com/eclipse-ee4j/parsson/pull/100nvdPatchWEB
- gitlab.eclipse.org/security/vulnerability-reports/-/issues/13nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-g8p6-p27c-52fxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-4043ghsaADVISORY
News mentions
0No linked articles in our index yet.