Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
Vulnerability Description
oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue has been patched in version(s)`3.1.2` & `3.2.0-beta.3`.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
oidcc 安全漏洞
Vulnerability Description
oidcc是The Erlang Ecosystem Foundation开源的一个 Erlang&Elixir 中的 OpenId Connect 客户端库。 oidcc 3.0.0及更高版本存在安全漏洞,该漏洞源于存在拒绝服务(DoS)漏洞。
CVSS Information
N/A
Vulnerability Type
N/A