CVE-2024-2410
Estado: AnalizadaCrítica (9.8)—
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has already been freed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-416
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-2410",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-2410",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-06-13T16:52:45.662270Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-coordination@google.com",
"affectedData": [
{
"repo": "https://github.com/protocolbuffers/protobuf",
"vendor": "protocolbuffers",
"product": "protobuf",
"versions": [
{
"status": "affected",
"version": "4.22.0",
"lessThan": "4.25.0",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:google:protobuf:-:*:*:*:*:*:*:*"
],
"vendor": "google",
"product": "protobuf",
"versions": [
{
"status": "affected",
"version": "4.22.0",
"lessThan": "4.25.0",
"versionType": "semver"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-03T13:15:21.700",
"references": [
{
"url": "https://github.com/protocolbuffers/protobuf/releases/tag/v25.0",
"tags": [
"Release Notes"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://github.com/protocolbuffers/protobuf/releases/tag/v25.0",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has already been freed. \n"
},
{
"lang": "es",
"value": "La función JsonToBinaryStream() es parte de la implementación de los búferes de protocolo C++ y se utiliza para analizar JSON de una secuencia. Si la entrada se divide en fragmentos separados de cierta manera, el analizador intentará leer bytes de un fragmento que ya ha sido liberado."
}
],
"lastModified": "2026-06-17T07:24:28.823",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8069127C-4FD6-4E80-A84A-28090748ACFC",
"versionEndExcluding": "4.25.0",
"versionStartIncluding": "4.22.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-coordination@google.com"
}