CVE-2024-22871
published 2024-02-29CVE-2024-22871: An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.53%
72.0th percentile
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clojure | clojure | — | — |
| clojure | clojure | >= 0 < 1.11.2-1 | 1.11.2-1 |
| clojure | clojure | >= 0 < 1.11.2-1 | 1.11.2-1 |
| clojure | clojure | >= 1.2.0 < 1.11.2 | 1.11.2 |
| debian | clojure | < clojure 1.11.2-1 (forky) | clojure 1.11.2-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
osv·2024-02-29
CVE-2024-22871 [HIGH] Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
Any program on the JVM may read serialized objects via [java.io.ObjectInputStream.readObject()](https://docs.oracle.com/javase/8/docs/api/java/io/ObjectInputStream.html#readObject--). Reading serialized objects from an untrusted source is **inherently unsafe** (this affects any program running on any version of the JVM) and is a prerequisite for this vulnerability.
Clojure classes that represent infinite seqs (Cycle, infinite Repeat, and Iterate) do not define hashCode() and use the parent ASeq.hashCode(), which walks the seq to compute the hash, yielding an infinite loop. Classes like java.util.HashMap call hashCode() on keys during deserialization of a serialized map
OSV
CVE-2024-22871: An issue in Clojure versions 1
osv·2024-02-29·CVSS 7.5
CVE-2024-22871 [HIGH] CVE-2024-22871: An issue in Clojure versions 1
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
GHSA
Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
ghsa·2024-02-29
CVE-2024-22871 [HIGH] CWE-502 Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
Any program on the JVM may read serialized objects via [java.io.ObjectInputStream.readObject()](https://docs.oracle.com/javase/8/docs/api/java/io/ObjectInputStream.html#readObject--). Reading serialized objects from an untrusted source is **inherently unsafe** (this affects any program running on any version of the JVM) and is a prerequisite for this vulnerability.
Clojure classes that represent infinite seqs (Cycle, infinite Repeat, and Iterate) do not define hashCode() and use the parent ASeq.hashCode(), which walks the seq to compute the hash, yielding an infinite loop. Classes like java.util.HashMap call hashCode() on keys during deserialization of a serialized map
Debian
CVE-2024-22871: clojure - An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a...
vendor_debian·2024·CVSS 7.5
CVE-2024-22871 [HIGH] CVE-2024-22871: clojure - An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a...
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.11.2-1)
sid: resolved (fixed in 1.11.2-1)
trixie: resolved (fixed in 1.11.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://hackmd.io/%40fe1w0/rymmJGidahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25FKUOYXQZGGJMFUM5HJABWMIX2TILRV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWWK2SO2MH4SXPO6L444MM6LHVLVFULV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YFPGUDXMW6OXKIDGCOZFEAXO74VQIB2T/https://hackmd.io/%40fe1w0/rymmJGidahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25FKUOYXQZGGJMFUM5HJABWMIX2TILRV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWWK2SO2MH4SXPO6L444MM6LHVLVFULV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YFPGUDXMW6OXKIDGCOZFEAXO74VQIB2T/https://lists.fedoraproject.org/archives/list/[email protected]/message/25FKUOYXQZGGJMFUM5HJABWMIX2TILRV/https://lists.fedoraproject.org/archives/list/[email protected]/message/SWWK2SO2MH4SXPO6L444MM6LHVLVFULV/https://lists.fedoraproject.org/archives/list/[email protected]/message/YFPGUDXMW6OXKIDGCOZFEAXO74VQIB2T/
2024-02-29
Published