Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h65f-jvqw-m9fj

Опубликовано: 27 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Infinite Loop in Apache Xerces Java

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

Пакеты

Наименование

xerces:xercesImpl

maven
Затронутые версииВерсия исправления

< 2.12.2

2.12.2

EPSS

Процентиль: 25%
0.00087
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-91

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
redhat
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
nvd
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

CVSS3: 6.5
debian
около 4 лет назад

There's a vulnerability within the Apache Xerces Java (XercesJ) XML pa ...

suse-cvrf
почти 4 года назад

Security update for xerces-j2

EPSS

Процентиль: 25%
0.00087
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-91