Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Exponential ReDoS in pymatgen leads to denial of service
Vulnerability Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
CWE-1333
Vulnerability Title
pymatgen 安全漏洞
Vulnerability Description
pymatgen是一个用于材料分析的开源 Python 库。 pymatgen 存在安全漏洞,攻击者利用该漏洞向 GaussianInput.from_string 方法提供任意输入时,可以触发指数 ReDoS。
CVSS Information
N/A
Vulnerability Type
N/A