A flaw was found in EAP-7 during deserialization of...
High severity
Unreviewed
Published
Dec 27, 2023
to the GitHub Advisory Database
•
Updated Jan 4, 2024
Description
Published by the National Vulnerability Database
Dec 27, 2023
Published to the GitHub Advisory Database
Dec 27, 2023
Last updated
Jan 4, 2024
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
References