Description
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.
Remediation
References
https://github.com/dromara/hutool/issues/3421
Related Vulnerabilities
CVE-2023-24621 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans
CVE-2020-17518 Vulnerability in maven package org.apache.flink:flink-runtime_2.11
CVE-2013-2071 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2015-9235 Vulnerability in npm package jsonwebtoken
CVE-2020-12827 Vulnerability in maven package org.webjars.npm:mjml