GHSA-gcg6-xv4f-f749
MODERATECVE-2023-33546janino 3.1.9 and earlier is subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, an attacker could supply content that causes the parser to crash due to a stack overflow.
- Affected
- <= 3.1.9
- Fixed in
- not stated
- Weakness
- CWE-787
- Published
- 2023-06-01
- Source
- github