PT-2022-27591 · Dromara · Dromara Hutool

Tgao

·

Published

2022-12-16

·

Updated

2024-01-25

·

CVE-2022-4565

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dromara HuTool versions up to 5.8.10
Description A vulnerability was found in Dromara HuTool that affects the file cn.hutool.core.util.ZipUtil.java, leading to resource consumption. The attack can be initiated remotely.
Recommendations For versions up to 5.8.10, upgrade to version 5.8.11 to address this issue.

Exploit

Fix

Resource Exhaustion

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2022-4565
GHSA-47VX-FQR5-J2GW

Affected Products

Dromara Hutool