Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmmq-j7pq-f85c

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

JRuby denial of service via Hash Collision

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.

Пакеты

Наименование

org.jruby:jruby-parent

maven
Затронутые версииВерсия исправления

< 1.7.1

1.7.1

EPSS

Процентиль: 69%
0.00604
Низкий

Дефекты

CWE-400

Связанные уязвимости

ubuntu
около 13 лет назад

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.

redhat
около 13 лет назад

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.

nvd
около 13 лет назад

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.

debian
около 13 лет назад

JRuby computes hash values without properly restricting the ability to ...

EPSS

Процентиль: 69%
0.00604
Низкий

Дефекты

CWE-400