Overview
About vulnerability
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.Details
- Affected product:
- Grafana , Loki , MinIO , buger/jsonparser , github.com/buger/jsonparser , grafana/grafana-plugin-sdk-go , grafana/grafana/pkg/promlib , invopop/jsonschema , wk8/go-ordered-map
- Affected packages:
- github.com/buger/jsonparser @ 1.1.1 (+11 more)