代码拉取完成,页面将自动刷新
【软件包名】
conmon
【CVE ID】
CVE-2024-28180
【漏洞评级】
Medium
【评分向量】
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
【CWE ID】
CWE-409
【漏洞描述】
Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.
【参考链接】