A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-27T00:00:00

Updated: 2024-08-02T22:32:09.101Z

Reserved: 2023-12-18T00:00:00

Link: CVE-2023-51079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-27T21:15:08.350

Modified: 2024-08-02T23:15:42.160

Link: CVE-2023-51079

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-27T00:00:00Z

Links: CVE-2023-51079 - Bugzilla