CVE-2022-41404
published 2022-10-11CVE-2022-41404: An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via…
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.36%
69.1th percentile
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ini4j | < ini4j 0.5.4-1 (bookworm) | ini4j 0.5.4-1 (bookworm) |
| ini4j_project | ini4j | < 0.5.4 | 0.5.4 |
| ini4j_project | ini4j | >= 0 < 0.5.4-1 | 0.5.4-1 |
| ini4j_project | ini4j | >= 0 < 0.5.4-1 | 0.5.4-1 |
| ini4j_project | ini4j | >= 0 < 0.5.4-1 | 0.5.4-1 |
| ini4j_project | ini4j | >= 0 < 0.5.4-1 | 0.5.4-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
org.ini4j allows attackers to cause a Denial of Service (DoS)
osv·2022-10-12
CVE-2022-41404 [HIGH] org.ini4j allows attackers to cause a Denial of Service (DoS)
org.ini4j allows attackers to cause a Denial of Service (DoS)
An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
GHSA
org.ini4j allows attackers to cause a Denial of Service (DoS)
ghsa·2022-10-12
CVE-2022-41404 [HIGH] CWE-400 org.ini4j allows attackers to cause a Denial of Service (DoS)
org.ini4j allows attackers to cause a Denial of Service (DoS)
An issue in the fetch() method in the BasicProfile class of org.ini4j before v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
OSV
CVE-2022-41404: An issue in the fetch() method in the BasicProfile class of org
osv·2022-10-11·CVSS 7.5
CVE-2022-41404 [HIGH] CVE-2022-41404: An issue in the fetch() method in the BasicProfile class of org
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Red Hat
org.ini4j: unspecified DoS
vendor_redhat·2022-10-12·CVSS 7.5
CVE-2022-41404 [HIGH] CWE-674 org.ini4j: unspecified DoS
org.ini4j: unspecified DoS
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
An infinite recursion vulnerability was found in the org.ini4j package. This flaw allows triggering the fetch() method to cause a denial of service.
Statement: While the org.ini4j may be susceptible to a denial of service, the way this package is utilized in Red Hat products limits the potential impact on the broader system.
Package: jenkins-2-plugins (OpenShift Developer Tools and Services) - Not affected
Package: org.arquillian.cube-arquillian-cube-parent (Red Hat Fuse 7) - Will not fix
Package: org.jboss.quickstarts.jdg-jboss-jdg-quickstarts (Red Hat JBoss Data Grid 7) - Will not fix
Pa
Debian
CVE-2022-41404: ini4j - An issue in the fetch() method in the BasicProfile class of org.ini4j through ve...
vendor_debian·2022·CVSS 7.5
CVE-2022-41404 [HIGH] CVE-2022-41404: ini4j - An issue in the fetch() method in the BasicProfile class of org.ini4j through ve...
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.5.4-1)
bullseye: resolved (fixed in 0.5.4-1)
forky: resolved (fixed in 0.5.4-1)
sid: resolved (fixed in 0.5.4-1)
trixie: resolved (fixed in 0.5.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2022/CVE-2022-41404https://lists.debian.org/debian-lts-announce/2022/11/msg00037.htmlhttps://sourceforge.net/p/ini4j/bugs/56/https://lists.debian.org/debian-lts-announce/2022/11/msg00037.htmlhttps://sourceforge.net/p/ini4j/bugs/56/
2022-10-11
Published