Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g256-87j3-gw89

Опубликовано: 15 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.

 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.

 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 30%
0.00113
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 30%
0.00113
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-674