Vulnerabilities > CVE-2023-51075 - Infinite Loop vulnerability in Hutool 5.8.23

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
hutool
CWE-835

Summary

hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.

Vulnerable Configurations

Part Description Count
Application
Hutool
1