Lucene search

K
osvGoogleOSV:GHSA-MQXP-CJR9-C5JM
HistoryOct 06, 2022 - 6:52 p.m.

JXPath Out-of-bounds Write vulnerability

2022-10-0618:52:04
Google
osv.dev
14
jxpath
vulnerability
denial of service

EPSS

0.001

Percentile

30.5%

Those using JXPath to interpret XPath may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

EPSS

0.001

Percentile

30.5%