漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
Vulnerability Description
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local execution. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
ANTLR 竞争条件问题漏洞
Vulnerability Description
ANTLR ANTLR是ANTLR团队的一款语法解析器生成框架。 ANTLR 4.13.2及之前版本存在竞争条件问题漏洞,该漏洞源于Maven Plugin组件中ObjectInputStream.readObject函数导致竞争条件(TOCTOU)问题。
CVSS Information
N/A
Vulnerability Type
N/A