Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39920
HistoryMar 23, 2023 - 7:21 p.m.

Denial Of Service (DoS)

2023-03-2319:21:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
denial of service
apache sling
resource merger
getrelativepath
mergedresourceprovider
iteration logic
infinite loop
cpu memory
system crash
vulnerability

0.002 Low

EPSS

Percentile

60.4%

Apache Sling Resource Merger is vulnerable to Denial of Service (DoS). The vulnerability is due to a faulty iteration logic in the function getRelativePath in MergedResourceProvider, triggering an infinite loop and consuming excessive CPU memory, possibly leading to a system crash.

0.002 Low

EPSS

Percentile

60.4%

Related for VERACODE:39920