Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Vulnerability Type
未经控制的递归
Vulnerability Title
Square Wire 安全漏洞
Vulnerability Description
Square Wire是美国Square开源的一个开源协议缓冲区处理库,主要用于高效的数据序列化和反序列化。 Square Wire 5.2.0之前版本存在安全漏洞,该漏洞源于未对嵌套组强制执行递归限制。
CVSS Information
N/A
Vulnerability Type
N/A