漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
Vulnerability Description
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server.
To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的递归
Vulnerability Title
AWS aws-smithy-json 资源管理错误漏洞
Vulnerability Description
AWS aws-smithy-json是AWS公司开源的一个JSON数据处理框架。 AWS aws-smithy-json 0.62.7之前版本存在资源管理错误漏洞,该漏洞源于未知键跳过路径中的未受控递归,可能导致远程未认证用户通过单个包含深度嵌套JSON的小型HTTP请求造成拒绝服务(进程因栈耗尽而中止)。
CVSS Information
N/A
Vulnerability Type
N/A