漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
regex injection leading to DoS
Vulnerability Description
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. Since the attacker controls the string and the regex pattern he may cause a ReDoS by regex catastrophic backtracking on the server side. This problem has been fixed in Roller 6.0.2.
CVSS Information
N/A
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Apache Roller 资源管理错误漏洞
Vulnerability Description
Apache Roller是美国阿帕奇(Apache)基金会的一套基于Java的多用户开源博客系统。 Apache Roller中存在安全漏洞。目前暂无该漏洞信息,请随时关注CNNVD或厂商公告。
CVSS Information
N/A
Vulnerability Type
N/A