PT-2022-7099 · Brondahl · Brondahl Enumstringvalues

Published

2022-12-21

·

Updated

2024-05-17

·

CVE-2020-36620

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Brondahl EnumStringValues versions up to 4.0.0 Brondahl EnumStringValues version 4.0.1
Description The issue is related to the function GetStringValuesWithPreferences Uncache of the file EnumStringValues/EnumExtensions.cs in the Brondahl EnumStringValues library. It is associated with uncontrolled resource consumption. Exploitation of this issue may allow a remote attacker to cause a denial of service. The manipulation leads to resource consumption.
Recommendations For Brondahl EnumStringValues versions up to 4.0.0, upgrade to version 4.0.1 to address this issue. For Brondahl EnumStringValues version 4.0.1, upgrade to version 4.0.2 to address this issue. As a temporary workaround, consider disabling the GetStringValuesWithPreferences Uncache function until a patch is available.

Fix

Resource Exhaustion

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-07575
CVE-2020-36620
GHSA-VQ23-HWG7-HXRH

Affected Products

Brondahl Enumstringvalues