{"id":"GHSA-hfg7-j82c-fr3w","summary":"Soot Infinite Loop vulnerability","details":"An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).","aliases":["CVE-2023-46442"],"modified":"2024-08-22T21:52:14.221531Z","published":"2024-05-24T20:09:40Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-24T20:09:40Z","nvd_published_at":"2024-05-24T17:15:45Z","cwe_ids":["CWE-400","CWE-835"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46442"},{"type":"WEB","url":"https://github.com/JAckLosingHeart/CVE-2023-46442_POC/tree/main"},{"type":"PACKAGE","url":"https://github.com/soot-oss/soot"}],"affected":[{"package":{"name":"org.soot-oss:soot","ecosystem":"Maven","purl":"pkg:maven/org.soot-oss/soot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.1"}]}],"versions":["4.1.0","4.2.0","4.2.1","4.3.0","4.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-hfg7-j82c-fr3w/GHSA-hfg7-j82c-fr3w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}