Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MVEL 安全漏洞
Vulnerability Description
MVEL是MVEL开源的一种混合动态/静态类型、可嵌入的表达式语言和 Java 平台运行时。 MVEL v2.5.0 Final版本存在安全漏洞,该漏洞源于ParseTools.subCompileExpression方法存在超时错误。
CVSS Information
N/A
Vulnerability Type
N/A