Bugzilla – Bug 1218430
VUL-1: CVE-2023-51079: mvel2: TimeOut error when calling ParseTools.subCompileExpression() function
Last modified: 2023-12-28 12:15:03 UTC
A TimeOut error exists in the ParseTools.subCompileExpression method in mvel2 v2.5.0 Final. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-51079 https://bugzilla.redhat.com/show_bug.cgi?id=2256065 https://github.com/mvel/mvel/issues/348
No fix from upstream yet. Setting the bug as VUL-1 because this requires the ability to input arbitrary code in the first place.