Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Neethi: Missing global alternative-output budget across policy computation paths
Vulnerability Description
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
CVSS Information
N/A
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Apache Neethi 资源管理错误漏洞
Vulnerability Description
Apache Software Foundation Apache Neethi是Apache Software Foundation基金会的消息队列中间件。 Apache Neethi 3.2.3之前版本存在资源管理错误漏洞,该漏洞源于通过特定构造的策略绕过最大规范化策略替代数限制,可能导致资源消耗引起拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A