Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22104
HistoryDec 05, 2019 - 6:34 a.m.

Denial Of Service (DoS)

2019-12-0506:34:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

38.0%

odata-client-core is vulnerable to denial of service (DoS). The attack is possible because AsyncResponseWrapperImpl class fails to validate the retryAfter value before directly parsing it to the Thread.sleep() method, allowing a malicious server to trigger an application crash via a huge value in the header.

CPENameOperatorVersion
odata-client-corele4.6.0

0.001 Low

EPSS

Percentile

38.0%

Related for VERACODE:22104