Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-41404

Опубликовано: 12 окт. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

An infinite recursion vulnerability was found in the org.ini4j package. This flaw allows triggering the fetch() method to cause a denial of service.

Отчет

While the org.ini4j may be susceptible to a denial of service, the way this package is utilized in Red Hat products limits the potential impact on the broader system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
Red Hat Fuse 7org.arquillian.cube-arquillian-cube-parentWill not fix
Red Hat JBoss Data Grid 7org.jboss.quickstarts.jdg-jboss-jdg-quickstartsWill not fix
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674->CWE-400

EPSS

Процентиль: 73%
0.00746
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 7.5
nvd
больше 3 лет назад

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 7.5
debian
больше 3 лет назад

An issue in the fetch() method in the BasicProfile class of org.ini4j ...

CVSS3: 7.5
github
больше 3 лет назад

org.ini4j allows attackers to cause a Denial of Service (DoS)

EPSS

Процентиль: 73%
0.00746
Низкий

7.5 High

CVSS3