Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-51079

Опубликовано: 27 дек. 2023
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mvel:mvel:2.5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00094
Низкий

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

CVSS3: 5.3
redhat
около 2 лет назад

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

CVSS3: 5.3
github
около 2 лет назад

mvel2 TimeOut error exists in the ParseTools.subCompileExpression method

EPSS

Процентиль: 27%
0.00094
Низкий

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo