This repository has been archived by the owner on Oct 2, 2023. It is now read-only.
CVE-2018-10237 (Medium) detected in guava-19.0.jar #123
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2018-10237 - Medium Severity Vulnerability
Vulnerable Library - guava-19.0.jar
Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more.
Library home page: https://github.com/google/guava
Dependency Hierarchy:
Found in HEAD commit: 7b16df0bfd847c502ac80c1464fe08140edf5d0d
Found in base branch: master
Vulnerability Details
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Publish Date: 2018-04-26
URL: CVE-2018-10237
CVSS 3 Score Details (5.9)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-10237
Release Date: 2018-04-26
Fix Resolution: 24.1.1-android
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: