Description
A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h63j-xqx6-w58r | mvel2 TimeOut error exists in the ParseTools.subCompileExpression method |
References
History
Wed, 25 Jun 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4::el6 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T22:32:09.101Z
Reserved: 2023-12-18T00:00:00.000Z
Link: CVE-2023-51079
No data.
Status : Modified
Published: 2023-12-27T21:15:08.350
Modified: 2024-11-21T08:37:48.567
Link: CVE-2023-51079
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA