cve/2023/CVE-2023-51079.md

19 lines
828 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-51079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-51079)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
** DISPUTED ** A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
### POC
#### Reference
- https://github.com/mvel/mvel/issues/348
- https://github.com/mvel/mvel/issues/348#issuecomment-1874047271
#### Github
No PoCs found on GitHub currently.