ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1.0.1.1"
}
],
"cpe": "cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "20.3.3"
},
{
"last_affected": "21.2.0"
}
],
"cpe": [
"cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:*"
],
"source": "CPE_FIELD"
}