Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38384
HistoryDec 09, 2022 - 3:36 a.m.

Denial Of Service (DoS)

2022-12-0903:36:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
denial of service
vulnerability
client hints
arrayindexoutofboundsexception
user-agent string
security issue

EPSS

0.001

Percentile

39.3%

yauaa is vulnerable to denial of service. The vulnerability exists due to ClientHintsAnalyzer.java improperly handling client hints, allowing an attacker to crash the application through the ArrayIndexOutOfBoundsException by passing a malicious user-agent string when using the client hint analysis feature.

EPSS

0.001

Percentile

39.3%

Related for VERACODE:38384