在 Google Guava 4.0 至 33.7.1 版本中,Java 对象反序列化过程存在无限制或未进行速率控制的资源分配问题(CWE-770),攻击者可由此导致拒绝服务(DoS)漏洞,表现为抛出 OutOfMemoryError。当反序列化 CompactHashMap、CompactHashSet 或 MapMakerInternalMap 实例时,Guava 会根据调用方指定的大小参数急切地分配数组,且未对此进行速率控制或限制,从而允许通过构造恶意序列化流耗尽内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet