Описание
VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue.
Ссылки
- ExploitThird Party Advisory
- Product
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:visicut:visicut:2.1:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00046
Низкий
3.3 Low
CVSS3
7.5 High
CVSS3
Дефекты
CWE-674
Связанные уязвимости
CVSS3: 3.3
github
10 месяцев назад
VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue.
EPSS
Процентиль: 14%
0.00046
Низкий
3.3 Low
CVSS3
7.5 High
CVSS3
Дефекты
CWE-674