Description
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Remediation
References
https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2022/CVE-2022-41404
https://lists.debian.org/debian-lts-announce/2022/11/msg00037.html
https://sourceforge.net/p/ini4j/bugs/56/
Related Vulnerabilities
CVE-2020-2274 Vulnerability in maven package org.jenkins-ci.plugins:elastestv
CVE-2020-28435 Vulnerability in npm package ffmpeg-sdk
CVE-2020-13929 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport
CVE-2014-6071 Vulnerability in maven package org.webjars:jquery