PT-2022-26316 · Unknown+1 · Mybatis Pagehelper+1

·

CVE-2022-42227

·

Published

2022-05-05

·

Updated

2023-01-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions jsonlint version 1.0 MyBatis PageHelper versions 3.5.x through 5.3.x
Description The issue involves a heap-buffer-overflow in jsonlint and a time-blind SQL injection vulnerability in MyBatis PageHelper. The jsonlint vulnerability occurs via the /home/hjsz/jsonlint/src/lexer file. In MyBatis PageHelper, the vulnerability is exploited via the orderBy parameter.
Recommendations For jsonlint version 1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For MyBatis PageHelper versions 3.5.x through 5.3.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider avoiding the use of the orderBy parameter in the affected API endpoint until the issue is resolved.

Exploit

Memory Corruption

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-42227
GHSA-W559-623P-VFG8

Affected Products

Mybatis Pagehelper
Jsonlint