CSSOM 在 0.5.0 及之前版本中存在一个拒绝服务(DoS)漏洞,该漏洞位于 方法中,由于未能正确验证保留属性名,攻击者可以提供一个包含名为 的声明的样式表,从而替换内部计数器,并在 序列化过程中触发过度的内存分配,最终导致进程终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet