« Volver al listado

CVE-2020-5234

Estado: ModificadaMedia (6.5)—

MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5234",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "neuecc",
          "product": "MessagePack",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.9.11"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.1.90"
            }
          ]
        },
        {
          "vendor": "neuecc",
          "product": "MessagePack.ImmutableCollection",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.9.11"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.1.90"
            }
          ]
        },
        {
          "vendor": "neuecc",
          "product": "MessagePack.ReactiveProperty",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.9.11"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.1.90"
            }
          ]
        },
        {
          "vendor": "neuecc",
          "product": "MessagePack.UnityShims",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.9.11"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.1.90"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-31T18:15:11.860",
  "references": [
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/commit/56fa86219d01d0a183babbbbcb34abbdea588a02",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/commit/f88684078698386df02204f13faeff098a61f007",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/issues/810",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/security/advisories/GHSA-7q36-4xx7-xcxf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/commit/56fa86219d01d0a183babbbbcb34abbdea588a02",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/commit/f88684078698386df02204f13faeff098a61f007",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/issues/810",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/neuecc/MessagePack-CSharp/security/advisories/GHSA-7q36-4xx7-xcxf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps."
    },
    {
      "lang": "es",
      "value": "MessagePack para C # y Unity anterior a la versión 1.9.11 y 2.1.90 tiene una vulnerabilidad en la que los datos no seguros pueden provocar un ataque DoS debido a colisiones hash y desbordamiento de pila. Revise el Aviso de seguridad de GitHub vinculado para obtener más información y pasos de reparación."
    }
  ],
  "lastModified": "2026-06-17T03:21:04.867",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E3E3D7A-9BC4-4387-9EBD-EE1DEE62266D",
              "versionEndExcluding": "1.9.3"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F24DBCF3-4F9D-4409-9343-7B258B4F1B3F",
              "versionEndExcluding": "2.1.80",
              "versionStartIncluding": "2.0.323"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.94:alpha:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5507008B-B8F8-4147-8E65-1481E479ABE6"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.110:alpha:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37BBAB86-0E12-4B68-A325-C168F7BB2C1C"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.119:beta:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1D65411-111F-4243-AFC7-F561CED839B7"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.123:beta:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D61D5CEA-5EB9-4C11-B379-604D8DE9F368"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.204:beta:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "129F03B4-C739-4EE9-ADCA-D9DC9337101E"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.270:rc:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6BB270F-6012-4C07-A070-E1F13048A439"
            },
            {
              "criteria": "cpe:2.3:a:messagepack:messagepack:2.0.299:rc:*:*:*:c\\#:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB524CF3-98FF-41DF-9C44-553ED740152D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}