Loading vulnerability details...
Application crashes with stack overflow when user use XML builder with prserveOrder:true for following or similar input
[{
'foo': [
{ 'bar': [{ '@_V': 'baz' }] }
]
}]
Cause: arrToStr was not validating if the input is an array or a string and treating all non-array values as text content.
What kind of vulnerability is it? Who is impacted?
Yes in 5.3.8
Use XML builder with preserveOrder:false or check the input data before passing to builder.
Application crashes with stack overflow when user use XML builder with prserveOrder:true for following or similar input
[{
'foo': [
{ 'bar': [{ '@_V': 'baz' }] }
]
}]
Cause: arrToStr was not validating if the input is an array or a string and treating all non-array values as text content.
What kind of vulnerability is it? Who is impacted?
Yes in 5.3.8
Use XML builder with preserveOrder:false or check the input data before passing to builder.
This low-severity vulnerability has limited impact but should still be addressed as part of regular security maintenance.
Probability of exploitation in the next 30 days · more likely than 49.9% of all CVEs.
Apply security patches to version 5.3.8, 4.5.4 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior