[MAVEN:GHSA-47VX-FQR5-J2GW] HuTool vulnerable to Uncontrolled Resource Consumption

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the file cn.hutool.core.util.ZipUtil.java. The manipulation leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.8.11 is able to address this issue. It is recommended to upgrade the affected component.

Package Affected Version
pkg:maven/cn.hutool/hutool-core < 5.8.11
Package Fixed Version
pkg:maven/cn.hutool/hutool-core = 5.8.11
ID
MAVEN:GHSA-47VX-FQR5-J2GW
Severity
high
URL
https://github.com/advisories/GHSA-47vx-fqr5-j2gw
Published
2022-12-16T21:30:44
(21 months ago)
Modified
2023-01-31T05:01:02
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/cn.hutool/hutool-core cn.hutool hutool-core < 5.8.11
Fixed pkg:maven/cn.hutool/hutool-core cn.hutool hutool-core = 5.8.11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...