CVE-2023-3040
Last modified
CVE-2023-3040 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug function was only used in tests and demos, it was not exploitable in a normal environment. . EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug function was only used in tests and demos, it was not exploitable in a normal environment.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Lua-Resty-Json | < 2023-05-05 |
References
- https://github.com/cloudflare/lua-resty-json/security/advisories/GHSA-h8rp-9622-83pgPatch, Third Party Advisory
- https://github.com/cloudflare/lua-resty-json/security/advisories/GHSA-h8rp-9622-83pgPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3040?
How severe is CVE-2023-3040?
How do I fix CVE-2023-3040?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30380An issue in the component /dialog/select_media.php of DedeCM…7.5
- CVE-2023-30382A buffer overflow in the component hl.exe of Valve Half-Life…7.3
- CVE-2023-30383TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Arche…7.5
- CVE-2023-3039 SD ROM Utility, versions prior to 1.0.2.0 contain an Improp…7.8
- CVE-2023-30394The MoveIt framework 1.1.11 for ROS allows cross-site script…6.1
- CVE-2023-30399Insecure permissions in the settings page of GARO Wallbox GL…8.1
- CVE-2023-30400An issue was discovered in Anyka Microelectronics AK3918EV30…9.8
- CVE-2023-30402YASM v1.3.0 was discovered to contain a heap overflow via th…5.5
- CVE-2023-30403An issue in the time-based authentication mechanism of Aigit…7.5
- CVE-2023-30404Aigital Wireless-N Repeater Mini_Router v0.131229 was discov…9.8
- CVE-2023-30405A cross-site scripting (XSS) vulnerability in Aigital Wirele…5.4
- CVE-2023-30406Jerryscript commit 1a2c047 was discovered to contain a segme…5.5
Are you affected by CVE-2023-3040?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
