Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h63j-xqx6-w58r

Опубликовано: 27 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

mvel2 TimeOut error exists in the ParseTools.subCompileExpression method

A TimeOut error exists in the ParseTools.subCompileExpression method in mvel2 v2.5.0 Final.

Пакеты

Наименование

org.mvel:mvel2

maven
Затронутые версииВерсия исправления

= 2.5.0.Final

Отсутствует

EPSS

Процентиль: 27%
0.00094
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

CVSS3: 5.3
redhat
около 2 лет назад

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

CVSS3: 5.3
nvd
около 2 лет назад

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

EPSS

Процентиль: 27%
0.00094
Низкий

5.3 Medium

CVSS3