CVE-2024-21634: Ion Java StackOverflow vulnerability
(updated )
A potential denial-of-service issue exists in ion-java for applications that use ion-java to:
- Deserialize Ion text encoded data, or
- Deserialize Ion text or binary encoded data into the
IonValuemodel and then invoke certainIonValuemethods on that in-memory representation.
An actor could craft Ion data that, when loaded by the affected application and/or processed using the IonValue model, results in a StackOverflowError originating from the ion-java library.
Impacted versions: <1.10.5
References
Code Behaviors & Features
Detect and mitigate CVE-2024-21634 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →