Description
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
Remediation
References
http://raneto.com/
https://cwe.mitre.org/data/definitions/703.html
https://gainsec.com/2022/08/04/cve-2022-35142-cve-2022-35143-cve-2022-35144/
https://github.com/gilbitron/Raneto/releases
Related Vulnerabilities
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-worker
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2016-10530 Vulnerability in npm package airbrake
CVE-2019-10174 Vulnerability in maven package org.infinispan:infinispan-commons
CVE-2017-12631 Vulnerability in maven package org.apache.cxf.fediz:fediz-spring3