漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Neethi: Circular Policy Reference Infinite Loop
Vulnerability Description
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition Users are recommended to upgrade to version 3.2.2, which fixes this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Apache Neethi 资源管理错误漏洞
Vulnerability Description
Apache Neethi是Apache基金会的一个策略处理框架库。 Apache Neethi存在资源管理错误漏洞,该漏洞源于未正确检测策略定义中的循环引用,可能导致策略规范化过程进入无限循环或过度递归,导致堆栈溢出或应用挂起。
CVSS Information
N/A
Vulnerability Type
N/A