CVE-2024-21634: Allocation of Resources Without Limits or Throttling
Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in ion-java
for applications that use ion-java
to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the IonValue
model and then invoke certain IonValue
methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the IonValue
model, results in a StackOverflowError
originating from the ion-java
library. The patch is included in ion-java
1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.
References
Detect and mitigate CVE-2024-21634 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →