oj is vulnerable to Out-of-bounds Write
59
Medium Risk
oj parses and dumps JSON with fixed size C buffers. A ^u Struct with too many member names, a deep array dumped with an integer indent, or a read that returns too many bytes writes past those buffers and corrupts stack or heap memory. A comment that runs to the end of the document reads past the buffer, and Oj::Doc on a document with no root uses a null pointer, so the process crashes. The fix stops at the end of each buffer and returns an error when the Struct class or document root is missing.
You are affected if you are using a version that falls within the vulnerable range and you use oj to parse untrusted data.
oj is vulnerable to Out-of-bounds Write in versions 1.3.7 - 3.17.3.
Upgrade the oj library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.