漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ion Java StackOverflow vulnerability
Vulnerability Description
Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that use `ion-java` to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the `IonValue` model and then invoke certain `IonValue` methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the `IonValue` model, results in a `StackOverflowError` originating from the `ion-java` library. The patch is included in `ion-java` 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Amazon Ion 安全漏洞
Vulnerability Description
Amazon Ion是美国亚马逊(Amazon)公司的一种类型丰富、自描述的分层数据序列化格式。提供可互换的二进制和文本表示形式。 Amazon Ion 1.10.5之前版本存在安全漏洞,该漏洞源于Ion Java存在堆栈溢出,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A