Description
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
Remediation
References
https://github.com/dromara/hutool/issues/3421
Related Vulnerabilities
CVE-2020-7706 Vulnerability in npm package connie-lang
CVE-2023-30532 Vulnerability in maven package org.jenkinsci.plugins.spoonscript:spoonscript
CVE-2017-16082 Vulnerability in maven package org.webjars.npm:pg
CVE-2020-28280 Vulnerability in npm package predefine
CVE-2021-28092 Vulnerability in maven package org.webjars.npm:is-svg