Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Function", "target": { "file": "src/main/java/com/erudika/scoold/controllers/ProfileController.java", "function": "updateUserPictureAndName" }, "signature_version": "v1", "digest": { "length": 622.0, "function_hash": "265660216317285609534752659757617058514" }, "id": "CVE-2022-1543-571cbfd3", "source": "https://github.com/erudika/scoold/commit/62a0e92e1486ddc17676a7ead2c07ff653d167ce" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/main/java/com/erudika/scoold/controllers/ProfileController.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "211629977491170619049913659508292615476", "211634383808851780241374717764239497067", "70968352504130803726974135255670138742", "67890799766719797059182751872168374139" ], "threshold": 0.9 }, "id": "CVE-2022-1543-7ed14a1c", "source": "https://github.com/erudika/scoold/commit/62a0e92e1486ddc17676a7ead2c07ff653d167ce" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/main/java/com/erudika/scoold/utils/ScooldUtils.java", "function": "updateProfilePictureAndName" }, "signature_version": "v1", "digest": { "length": 619.0, "function_hash": "252112291235173890737571049669118148592" }, "id": "CVE-2022-1543-cbb6f020", "source": "https://github.com/erudika/scoold/commit/62a0e92e1486ddc17676a7ead2c07ff653d167ce" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/main/java/com/erudika/scoold/utils/ScooldUtils.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "114655733348253043509686436875016073465", "321101153080300775535344413051179694896", "287180865918966036129481927995005396904", "261645096287423575722412681268790409521" ], "threshold": 0.9 }, "id": "CVE-2022-1543-d128eb09", "source": "https://github.com/erudika/scoold/commit/62a0e92e1486ddc17676a7ead2c07ff653d167ce" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/main/java/com/erudika/scoold/core/Profile.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "339690704184666715930920932127198628117", "112533359272343193184409164038332253042", "158404882985283570244258977911168951270", "40350836642989822946880062270326706170" ], "threshold": 0.9 }, "id": "CVE-2022-1543-dc3b41a2", "source": "https://github.com/erudika/scoold/commit/62a0e92e1486ddc17676a7ead2c07ff653d167ce" } ] }