Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cw56-j3fm-7w57

Опубликовано: 18 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Regular expression denial of service in Apache ShenYu

In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.

Пакеты

Наименование

org.apache.shenyu:shenyu

maven
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.3

2.4.3

Наименование

org.apache.shenyu:shenyu-bootstrap

maven
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.3

2.4.3

EPSS

Процентиль: 79%
0.01258
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-862

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.

EPSS

Процентиль: 79%
0.01258
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-862