Description
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
Remediation
References
https://github.com/dromara/hutool/issues/3421
Related Vulnerabilities
CVE-2022-25645 Vulnerability in maven package org.webjars.npm:dset
CVE-2021-33561 Vulnerability in maven package com.shopizer:shopizer
CVE-2022-31160 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2022-45689 Vulnerability in maven package cn.hutool:hutool-json
CVE-2020-5259 Vulnerability in maven package org.webjars.bower:dojox