漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
Vulnerability Description
The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process termination through stack overflow in Microsoft.OpenApi. The issue affects OpenAPI document parsing through public OpenAPI.NET reader APIs and has been confirmed across both JSON and YAML reader paths. This vulnerability is fixed in 2.7.5 and 3.5.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的递归
Vulnerability Title
microsoft OpenAPI.NET 资源管理错误漏洞
Vulnerability Description
Microsoft OpenAPI.NET是美国Microsoft公司的一个用于处理OpenAPI规范的库。 Microsoft OpenAPI.NET 2.0.0-preview11版本至2.7.5之前版本和3.0.0版本至3.5.4之前版本存在资源管理错误漏洞,该漏洞源于包含循环模式引用的OpenAPI文档可能导致通过堆栈溢出终止进程。
CVSS Information
N/A
Vulnerability Type
N/A