A remote, anonymous attacker can exploit a vulnerability in jq to perform a Denial of Service attack.
| Vendor | Product | Versions |
|---|---|---|
| jqlang | jq | < 1.8.2 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | jq | cert_advisory | 90% |
Updated description to include Denial of Service attack and marked exploit as available and actively exploited.
Updated severity to CRITICAL, noted that no exploit exists, and specified the fixed version as 1.8.2.
Initial creation