Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rc44-5cmh-879m

Опубликовано: 25 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Unrestricted recursion in htmlunit

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack. This issue affects HtmlUnit before 2.70.0.

Пакеты

Наименование

org.htmlunit:htmlunit

maven
Затронутые версииВерсия исправления

< 2.70.0

2.70.0

EPSS

Процентиль: 22%
0.00073
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-787

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit before 2.70.0.

CVSS3: 7.5
redhat
больше 2 лет назад

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit before 2.70.0.

CVSS3: 7.5
nvd
больше 2 лет назад

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit before 2.70.0.

CVSS3: 7.5
debian
больше 2 лет назад

Those using HtmlUnit to browse untrusted webpages may be vulnerable to ...

EPSS

Процентиль: 22%
0.00073
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-787