漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM
Vulnerability Description
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload declaring an arbitrarily large decompressed size in a retry task argument, causing the JVM to attempt an unbounded array allocation and triggering an unrecoverable java.lang.OutOfMemoryError when the task is dispatched through the retry-task pipeline.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的内存分配
Vulnerability Title
aizuda SnailJob 资源管理错误漏洞
Vulnerability Description
aizuda SnailJob是aizuda组织开源的一个灵活、可靠且高效的分布式任务重试和任务调度平台。 aizuda SnailJob 1.7.0版本存在资源管理错误漏洞,该漏洞源于FuryUtil.deserialize助手在处理特制的Zstandard压缩payload时未正确验证frame header中的frame_content_size字段,导致JVM尝试无界数组分配并触发不可恢复的java.lang.OutOfMemoryError,允许认证攻击者导致服务器崩溃。
CVSS Information
N/A
Vulnerability Type
N/A