Executive brief
snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
Affected products
- Maven org.xerial.snappy:snappy-java
Junglewise Threat Intelligence
CVE-2023-43642 · Severity: low · CVSS 3.1 · Published 2023-09-25
Technologies: org.xerial.snappy:snappy-java (Maven). Vendors: Maven.
snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact