CVE Vulnerabilities

CVE-2023-51079

Published: Dec 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because the only thing that you could expect is that the parser will take a crazy amount of time to complete its task.

Affected Software

Name Vendor Start Version End Version
Mvel Mvel 2.5.0 (including) 2.5.0 (including)
Red Hat build of Apache Camel 4.4.1 for Spring Boot RedHat mvel *
Mvel Ubuntu bionic *
Mvel Ubuntu lunar *
Mvel Ubuntu mantic *
Mvel Ubuntu trusty *
Mvel Ubuntu xenial *

References