An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| net.minidev:json-smart(Maven) | 0 | 1.3.2 | N/A |
| net.minidev:json-smart(Maven) | 2.4.0 | 2.4.1 | N/A |
| net.minidev:json-smart-mini(Maven) | 0 | 1.3.2 | N/A |
| net.minidev:json-smart(Maven) | 2.0.0 | 2.3.1 | N/A |
CVSS Metrics