CVE-2020-5234

MEDIUMCVSS 6.5/10EPSS 1.58%

Last modified

CVE-2020-5234 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.. EPSS estimates a 1.58% chance of exploitation in the next 30 days.

Description

MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.58%

72.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
MessagepackMessagepack< 1.9.3
MessagepackMessagepack>= 2.0.323, < 2.1.80
MessagepackMessagepack2.0.94Alpha
MessagepackMessagepack2.0.110Alpha
MessagepackMessagepack2.0.119Beta
MessagepackMessagepack2.0.123Beta
MessagepackMessagepack2.0.204Beta
MessagepackMessagepack2.0.270Rc
MessagepackMessagepack2.0.299Rc

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-5234?
MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.
How severe is CVE-2020-5234?
CVE-2020-5234 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.58% probability of exploitation in the next 30 days.
How do I fix CVE-2020-5234?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-5234?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST