CVE-2022-26650
CVSS v3.1
7.5 (High)
CVSS v2.0
5 (Medium)
EPSS
0.13 % (48th)
Affected Products
1
Advisories
1
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.
Weaknesses
- CWE-1333
- Inefficient Regular Expression Complexity
- CVE Status
- PUBLISHED
- CNA
- Apache Software Foundation
- Published Date
-
2022-05-17 08:15:06
(2 years ago) - Updated Date
-
2023-07-12 11:15:09
(14 months ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...