Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h65f-jvqw-m9fj

Опубликовано: 27 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Infinite Loop in Apache Xerces Java

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Пакеты

Наименование

xerces:xercesImpl

maven
Затронутые версииВерсия исправления

< 2.12.2

2.12.2

EPSS

Процентиль: 90%
0.0444
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-91

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
redhat
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
nvd
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
debian
больше 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML pa ...

suse-cvrf
больше 4 лет назад

Security update for xerces-j2

EPSS

Процентиль: 90%
0.0444
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-91