ZeroHour

CVE-2021-27290

PoC ×2
CVSS 3.1
7.5 high
EPSS
5%p91
Published
()
Modified
Description

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Vendors
ssri projectoraclesiemens
Products
ssri, graalvm, sinec infrastructure network services
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.